idle-tokens

1 article
sort: new top best
clear filter
0 7/10
vulnerability

A critical price oracle manipulation vulnerability was discovered in Enzyme Finance's Idle token pricing mechanism, where flashloans from IdleTokenGovernance.sol could manipulate the totalSupply calculation used in price computation (totalNav/totalSupply), allowing attackers to exploit share buying. The bug was introduced in Idle v5 when flashloan logic was added, and the researcher received a $90,000 bounty for reporting with a working proof-of-concept.

Enzyme Finance Immunefi setuid0 SSLab Georgia Tech IdleTokenGovernance.sol ComptrollerLib.sol VaultInterpreter.sol IDerivativePriceFeed.sol IdlePriceFeed.sol Aave Uniswap Chainlink
medium.com · unknown · 23 hours ago · details