Ellipsis Finance ·BSC
IncentiveVoting.createTokenApprovalVote() reentrancy
Verified with working PoC
Contract: 0x4695e50A38E33Ea09D1F623ba8A8dB24219bb06a
Summary
The external call target inside createTokenApprovalVote() (_token.minter() -> pool.withdraw_admin_fees()) is a raw, caller-supplied parameter rather than a fixed address - fully attacker-controlled, unlike a sibling finding on the same run that turned out to be a false positive precisely because its call target was immutable and hookless.
Root cause
State (lastVote, tokenApprovalVotes) is written after the external call, and the call destination is chosen by the caller, not the protocol - a genuine CEI violation with an exploitable target, not just a structural pattern match.
Verification
Built a real Foundry PoC: deployed a malicious _token/pool pair, called createTokenApprovalVote, and confirmed the callback successfully reentered and pushed its own vote entry mid-call - run against live forked BSC state (tokenApprovalVotes.length continued from the real on-chain value, not a fresh deploy).
Verified against real, live deployed contract state.
Receipt on GitHub