curve-pool

1 article
Sort: New Top Best
clear filter
0
bug-bounty

A security researcher earned $10,000 on Immunefi by discovering two related vulnerabilities in DFX Finance: unhandled fee-on-transfer (FoT) tokens that drain liquidity from USDC pairs, and risks from USDC being upgradable, which could introduce breaking changes to the protocol. The submission succeeded through a functional proof-of-concept, real-world impact examples, and actionable remediation recommendations.

DFX Finance Beirao Code4Arena Immunefi Trail of Bits USDC EURT GYEN PAXG USDT Uniswap SEC
beirao.xyz · Beirao · 4 hours ago · details