The malicious library solmate-bad
allows the owner of address 0x815F577F1c1bcE213c012f166744937C889DAF17
to move funds via the transferFrom
function from any address to any address.
In the malicious library solmate-bad
, the src/tokens/ERC20.sol
is modified from the original solmate
library where the transferFrom
function allows the owner of address 0x815F577F1c1bcE213c012f166744937C889DAF17
to move funds from any address they choose.
Potential loss of all funds.
Manual review
Replace malicious library from https://github.com/PatrickAlphaC/solmate-bad to https://github.com/transmissions11/solmate
Some sneaky elf has changed this library to a corrupted one where his wallet address skips all the approval checks for SantaToken! Shenanigans here - https://github.com/PatrickAlphaC/solmate-bad/blob/c3877e5571461c61293503f45fc00959fff4ebba/src/tokens/ERC20.sol#L88
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.