integer-division

1 article
sort: new top best
clear filter
0 6/10
bug-bounty

DFX Finance had a critical rounding error vulnerability in the AssimilatorV2 contract where integer division could result in zero tokens being transferred while still minting LP tokens to the attacker. By exploiting the non-standard 2-decimal EURS token, an attacker could repeatedly deposit minimal amounts and drain approximately $237,143 from the vulnerable pool.

DFX Finance EURS USDC Immunefi perseverance AssimilatorV2 Chainlink Alejandro Muñoz-McDonald
medium.com · unknown · 6 hours ago · details