All reports
highFront-running / MEVEVM-Solidity

Tapioca DAO: `BaseTOFT.sol`: `retrieveFromStrategy` can be used to manipulate other user's positions due to absent approval check

Payout
$0
Protocol
Tapioca DAO
Disclosed
Nov 16, 2023
Source
code4rena

A critical authorization flaw exists in the Tapioca DAO cross-chain architecture where the BaseTOFT contract fails to validate user allowances during the initiation of cross-chain strategy withdrawals. By manipulating the from parameter in the retrieveFromStra …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.