Closed sherlock-admin2 closed 1 month ago
Spam/bot submission?
@telome thank you i am real human manual review thank you for comment please tag on discord we will read everything fast and may you ask if any further query. @0xaliyah
@telome if your asking if the attacker will spam/brute force . as if have discussed at #14 I am not suspecting it will be the most elegant approach by the attacker.
0xaliyah
High
h-03 reentrant with stolen of funds 0xaliyah
Summary
balance
L197 is the misinformation toward the effect at L201balance
L197 is the lagging indication toward the effect at L201 if themsg.sender
address was made any withdrawal or any transferFrom in the way that induced that reentrymsg.sender
address made a withdrawal when thetransfer
function gave up control to the attacker at L197msg.sender
is now emptied since L197 capturing and L197 now stale then L201 give themsg.sender
address free incrementVulnerability Detail
Impact
Code Snippet
poc
Tool used
Manual Review
Recommendation
checks effects interactions Will Shahda
Duplicate of #14