deposit-withdrawal

1 article
sort: new top best
clear filter
0 7/10
vulnerability

Beanstalk's convertFacet function failed to validate the Well address parameter, allowing attackers to supply a malicious contract that could return arbitrary BEAN amounts and set conversion costs to zero, enabling theft of protocol funds without proper token withdrawal. The fix added validation to ensure the Well address is whitelisted and that the fromAmount is always non-zero.

Beanstalk Immunefi BEAN convertFacet Silo Well
medium.com · unknown · 19 hours ago · details