DefimonAlerts
@DefimonAlerts · 2026-05-05
Ekubo v2 locker blindly trusts the from address embedded in the locker's packed instruction payload. Its payCallback(token,id,_,amount,from) does a transferFrom with from taken straight from user-supplied calldata.