crypto-protocol

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A state-machine vulnerability in Fluidity's reward distribution system allows double-claiming of rewards through improper handling of out-of-order batch reward transactions combined with manual reward claims, exploitable when multiple batchReward() calls arrive in the mempool for different block ranges.

Fluidity fUSDC AAVE Compound Token.sol WorkerConfig.sol CompoundLiquidityProvider.sol AaveV3LiquidityProvider.sol
trust-security.xyz · Trust · 17 hours ago · details