flashloan-attack

2 articles
sort: new top best
clear filter
0 5/10
vulnerability

Vesu disclosed a critical rounding convention vulnerability in the Singleton contract's liquidate_position function that could allow fund theft through malicious pool extensions, flashloans, and receive_as_shares flag manipulation. The vulnerability was remediated by removing the affected liquidation logic, whitelisting pool extensions, and migrating all user funds.

Vesu Immunefi Argent Labs ChainSecurity Re7 Labs Braavos Alterscope
docs.vesu.xyz · Alex · 15 hours ago · details
0 7/10
bug-bounty

Enzyme Finance had a critical price oracle manipulation vulnerability in Idle token pricing where flashloans could manipulate the totalSupply used in price calculations (totalNav/totalSupply). Researcher setuid0 discovered and reported the bug with a working PoC, earning a $90,000 bounty.

Enzyme Finance Immunefi setuid0 SSLab Georgia Tech IdleTokenGovernance.sol IdlePriceFeed.sol ComptrollerLib.sol VaultInterpreter.sol IDerivativePriceFeed.sol Aave Uniswap Sushiswap PancakeSwap Curve Bancor Balancer Chainlink
medium.com · unknown · 15 hours ago · details