account-state-manipulation

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A critical vulnerability in marginfi's flash loan mechanism allowed attackers to borrow funds without repayment by exploiting a new `transfer_to_new_account` instruction that could reset account state during an active flash loan, bypassing health checks. The vulnerability put $160M in deposits at risk and was responsibly disclosed and patched.

marginfi marginfi-v2 Felix Wilhelm Solana
blog.asymmetric.re · Felix Wilhelm · 17 hours ago · details