reentrancy-adjacent

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A critical vulnerability in Tranchess's ShareStaking contract allowed attackers to drain user funds by exploiting a skipped _checkpoint() call during rebalance events, causing total supply desynchronization. The attack enables direct theft of up to 815 BTC and 1438 ETH depending on attacker's fund size, with exploitation possible via frontrunning the rebalance settlement.

Tranchess ShareStaking FundV3 Immunefi Queen Bishop Rook BSC
github.com · Flora · 17 hours ago · details