constant-product-formula

1 article
Sort: New Top Best
clear filter
0
vulnerability

A privilege escalation vulnerability in Tokemak's liquidity controllers allows attackers with ADD_LIQUIDITY_ROLE to steal protocol funds by manipulating pool ratios and exploiting the deploy() function's lack of price validation. The attack creates a malicious liquidity pool with a skewed token ratio, triggers the controller to deposit at the bad ratio, then extracts tokens through swaps, potentially stealing entire reserve amounts of FOX and ALCX tokens.

Tokemak SushiswapControllerV2 UniswapController Chainlink FOX ALCX
trust-security.xyz · Trust · 4 hours ago · details