Platform: Code4rena
Start Date: 27/04/2022
Pot Size: $50,000 MIM
Total HM: 6
Participants: 59
Period: 5 days
Judge: 0xean
Id: 113
League: ETH
Rank: 44/59
Findings: 1
Award: $72.42
🌟 Selected for report: 0
🚀 Solo Findings: 0
🌟 Selected for report: IllIllI
Also found by: 0x1337, 0x1f8b, 0xDjango, 0xf15ers, AuditsAreUS, BowTiedWardens, CertoraInc, Funen, GimelSec, MaratCerby, Ruhum, WatchPug, antonttc, berndartmueller, bobi, bobirichman, broccolirob, catchup, cccz, defsec, delfin454000, gs8nrv, gzeon, horsefacts, hubble, hyh, ilan, jah, joestakey, kebabsec, kenta, kenzo, m9800, mics, oyc_109, pauliax, reassor, robee, samruna, sikorico, simon135, throttle, unforgiven, z3s
72.4178 MIM - $72.42
The NFTPair.sol uses transferFrom to transfer ERC721 after repaying or removing collateral so if a user isn't aware of the incoming ERC721 token the NFT can get locked forever
https://github.com/code-423n4/2022-04-abranft/blob/5cd4edc3298c05748e952f8a8c93e42f930a78c2/contracts/NFTPair.sol#L266 https://github.com/code-423n4/2022-04-abranft/blob/5cd4edc3298c05748e952f8a8c93e42f930a78c2/contracts/NFTPair.sol#L266
Manual
use safeTransferFrom
#0 - cryptolyndon
2022-05-05T21:25:43Z
Duplicate of #20
#1 - 0xean
2022-05-21T15:10:13Z
see #20 - downgrading to QA
#2 - JeeberC4
2022-05-23T19:03:19Z
Preserving original title: use of transferFrom