58124 sc low direct theft of funds via malicious actions in execute call due to incorrect calldata verification
Description
Brief/Intro
Vulnerability Details
function execute(
SlippageAndActions calldata slippage,
bytes[] calldata actions,
bytes32 affiliateData
) external;Impact Details
References
Proof of Concept
Proof of Concept
Previous57532 sc high assets are not accounted for when the contract is in killswitch modeNext57926 sc low the conditional strategydeallocationloss event in morphoyearnogwethstrategy deallocate gets logged all the time due a misplacement in variable declaration
Was this helpful?