performance-fee-bug

1 article
sort: new top best
clear filter
0 5/10
bug-bounty

Brahma vault's collectFees() function incorrectly charges performance fees on gains without accounting for losses, causing users to lose portions of their original deposits during volatile market conditions. The bug stems from not tracking maximum share price per user or accumulated losses, allowing fees to be extracted from principal rather than only from actual profits.

Brahma 0x3c4Fe0db16c9b521480c43856ba3196A9fa50E08 Immunefi Enso Finance code-423n4
trust-security.xyz · Trust · 17 hours ago · details