All findings

Ellipsis Finance ·BSC

IncentiveVoting.createTokenApprovalVote() reentrancy

Medium

Verified with working PoC

Contract: 0x4695e50A38E33Ea09D1F623ba8A8dB24219bb06a

reentrancyCEI violationgovernance

Summary

The external call target inside createTokenApprovalVote() (_token.minter() -> pool.withdraw_admin_fees()) is a raw, caller-supplied parameter rather than a fixed address - fully attacker-controlled, unlike a sibling finding on the same run that turned out to be a false positive precisely because its call target was immutable and hookless.

Root cause

State (lastVote, tokenApprovalVotes) is written after the external call, and the call destination is chosen by the caller, not the protocol - a genuine CEI violation with an exploitable target, not just a structural pattern match.

Verification

Built a real Foundry PoC: deployed a malicious _token/pool pair, called createTokenApprovalVote, and confirmed the callback successfully reentered and pushed its own vote entry mid-call - run against live forked BSC state (tokenApprovalVotes.length continued from the real on-chain value, not a fresh deploy).

Verified against real, live deployed contract state.

Receipt on GitHub