MorpheusAI

MorpheusAI
Foundry
22,500 USDC
View results
Submission Details
Severity: high
Invalid

[H-1] - Initializer front-running in `L2TokenReceiver` contract

Summary

Malicious user can front-run the L2TokenReceiver__init() initializer function

Vulnerability Details

After the front-running, the user can swap unlimited amount of tokens essentially for free, before the redeployment
of the protocol

Impact

Significant tokenOut losses

Tools Used

Manual review

Recommendations

Implement valid access control on the L2TokenRecivercontract to ensure only the relevant deployer can call L2TokenReceiver__init function.

Updates

Lead Judging Commences

inallhonesty Lead Judge
over 1 year ago
inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Known issue

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.