ape-staking

1 article
sort: new top best
clear filter
0 8/10
vulnerability

BendDAO's Sewer Pass Flash Claim contract contained an input validation vulnerability where the `airdropTokenAddresses` parameter was not validated against a whitelist, allowing NFT owners to deploy malicious token contracts that could withdraw staked ApeCoin during the flash loan execution without proper unstaking.

BendDAO Sewer Pass BAYC MAYC ApeCoin Ape Staking UserFlashclaimRegistryV3 AirdropFlashLoanReceiverV3 CVE-ID-16841
medium.com · unknown · 17 hours ago · details