highBridge exploitEVM-Solidity
Tapioca DAO: Attacker can pass duplicated reward token addresses to steal the reward of contract `twTAP.sol`
- Payout
- $0
- Protocol
- Tapioca DAO
- Disclosed
- Nov 16, 2023
- Source
- code4rena
A vulnerability in Tapioca DAO's twTAP contract allows attackers to drain contract reward balances by passing duplicate reward token addresses. The internal function responsible for processing reward claims snapshots claimable amounts before iterating over a c …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-07-tapioca-findings/issues/1094
- https://github.com/code-423n4/2023-07-tapioca-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.