delegation-bug

1 article
sort: new top best
clear filter
0 8/10
bug-bounty

APWine's PT token implementation had a critical logic flaw in the beforeTokenTransfer() hook that failed to validate delegation amounts during token burns, allowing attackers to inflate delegated yield tokens and steal protocol yield by repeatedly depositing, delegating, and withdrawing without proper balance checks.

APWine Immunefi setuid0 SSLab@Gatech ERC20
medium.com · unknown · 17 hours ago · details