fcash

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A critical smart contract vulnerability in Notional V2 allowed double-counting of free collateral in bitmap portfolio processing, enabling attackers to drain protocol liquidity by borrowing against overstated collateral. The bug was triggered via sequential calls to enableBitmapForAccount() and depositUnderlyingToken() that caused free collateral calculations to run twice on the same asset.

Notional V2 0x60511e57 Immunefi DAI USDC Ethereum cDAI cUSDC fCash
medium.com · 0x60511e57 · 23 hours ago · details