reward-calculation

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A logic error in Tidal Finance's staking contract on Polygon allowed attackers to claim unearned rewards by exploiting improper state management in the payout process, where user.rewardDebt remained zero after a finalized payout. The vulnerability was patched by moving a critical rewardDebt update line earlier in the execution flow.

Tidal Finance Immunefi Csanuragjain Polygon
medium.com · csanuragjain · 23 hours ago · details