All reports
mediumLogic errorEVM-Solidity

Panoptic: ` validateCallback()` is vulnerable to a birthday attack

Payout
$0
Protocol
Panoptic
Disclosed
Jun 24, 2024
Source
code4rena

Panoptic validates Uniswap V3 callbacks by deriving the expected pool address from caller-supplied PoolFeatures via a keccak256 CREATE2-style computation and comparing it to msg.sender. Because keccak256 yields 256-bit outputs while addresses are 160 bits, rou …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.