All reports
highLogic errorEVM-Solidity

reNFT: Malicious actor can steal any actively rented NFT and freeze the rental payments (of the affected rentals) in the `escrow` contract

Payout
$0
Protocol
reNFT
Disclosed
Mar 20, 2024
Source
code4rena

reNFT's rental-stop lifecycle contains three interacting flaws that together let an attacker steal any currently-rented NFT and freeze the victim's rental payments in escrow. stopRent validates the fabricated RentalOrder only by orderType, endTimestamp and len …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.