Maia DAO - Ulysses - stuxy's results

Harnessing the power of Arbitrum, Ulysses Omnichain specializes in Virtualized Liquidity Management.

General Information

Platform: Code4rena

Start Date: 22/09/2023

Pot Size: $100,000 USDC

Total HM: 15

Participants: 175

Period: 14 days

Judge: alcueca

Total Solo HM: 4

Id: 287

League: ETH

Maia DAO

Findings Distribution

Researcher Performance

Rank: 170/175

Findings: 1

Award: $0.11

🌟 Selected for report: 0

🚀 Solo Findings: 0

Lines of code

https://github.com/code-423n4/2023-09-maia/blob/f5ba4de628836b2a29f9b5fff59499690008c463/src/VirtualAccount.sol#L85

Vulnerability details

Impact

payableCall function is missing requiresApprovedCaller modifier. Anyone can call it and transfer the contract's tokens to themselves, or make other malicious calls from it.

Tools Used

Manual Testing

Add requiresApprovedCaller access modifier to the function.

Assessed type

Access Control

#0 - c4-pre-sort

2023-10-08T14:29:23Z

0xA5DF marked the issue as duplicate of #888

#1 - c4-pre-sort

2023-10-08T14:57:10Z

0xA5DF marked the issue as sufficient quality report

#2 - c4-judge

2023-10-26T11:31:02Z

alcueca marked the issue as satisfactory

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter