mediumLogic errorEVM-Solidity
Exactly Protocol: borrow() maliciously let others to enter market
- Payout
- $0
- Protocol
- Exactly Protocol
- Disclosed
- May 4, 2024
- Source
- sherlock
In Exactly Protocol's Market contract, the borrow() function lacked a check that the assets argument is non-zero. Because spendAllowance() is skipped when assets is zero, any caller — without any approval from the borrower — could invoke borrow(0, receiver, vi …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.