initialization-flaw

1 article
sort: new top best
clear filter
0 7/10
vulnerability

Iron Bank's CCollateralCapERC20 token fails to enforce the collateral cap invariant during account initialization, allowing totalCollateralTokens to exceed collateralCap limits and creating liquidation insolvency risks. The initializeAccountCollateralTokens() function bypasses the cap check that is properly enforced elsewhere, enabling uninitialized users to receive collateral without cap validation.

Iron Bank CCollateralCapERC20 0x00e5c0774A5F065c285068170b20393925C84BF3
trust-security.xyz · Trust · 23 hours ago · details