First Flight #16: Mafia Takedown

Beginner FriendlyDeFiFoundry
100 EXP
Submission Details
Severity: high
Valid

In `MoneyShelf::depositUSDC` function, it is used an arbitrary `from` passed to `transferFrom` and thhe `to` address is not the `msg.sender`

Updates

Lead Judging Commences

n0kto Lead Judge 4 months ago
Submission Judgement Published
Validated
Assigned finding tags:

Arbitrary account deposit, steal approval

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.