token-transfer

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A critical logic error in Beanstalk's Token Facet transferTokenFrom() function allowed attackers to steal ERC20 tokens from approved accounts by bypassing allowance checks for external transfers. The vulnerability risked $3.1M in assets but was responsibly disclosed and patched before exploitation.

Beanstalk Immunefi Token Facet LibBalance LibTransfer EBIP-6 Foundry
medium.com · unknown · 23 hours ago · details