code-423n4 / 2021-10-tally-findings

0 stars 0 forks source link

Transfer function is unreliable #69

Closed code423n4 closed 2 years ago

code423n4 commented 2 years ago

Handle

Koustre

Vulnerability details

Impact

Opcode pricing is not stable and should not be relied upon to protect against re-entrancy attacks.

Proof of Concept

Provide direct links to all referenced code in GitHub. Add screenshots, logs, or any other relevant proof that illustrates the concept.

Tools Used

Recommended Mitigation Steps

Replace all uses of transfer with other techniques to sending ether, such as sendValue

Shadowfiend commented 2 years ago

Duplicate of #20.