arithmetic-error

1 article
sort: new top best
clear filter
0 7/10
vulnerability

Two critical rounding errors in The Graph's smart contracts allowed attackers to avoid paying curation taxes and bypass token lock durations through batch processing of small amounts. The vulnerabilities were patched after responsible disclosure by whitehat @GregadETH, resulting in a $290,497 bug bounty.

The Graph GregadETH Immunefi Curation.sol L2Curation.sol L2Staking.sol MathUtils.sol GRT Arbitrum
medium.com · GregadETH · 22 hours ago · details