savior-contracts

1 article
sort: new top best
clear filter
0 7/10
RAI
vulnerability

A critical returndata bomb vulnerability in RAI's LiquidationEngine allows malicious savior contracts to crash liquidations by reverting with massive return data, causing out-of-gas errors and creating unliquidatable positions that lead to protocol bad debt. The vulnerability was acknowledged as technically valid but dismissed as out-of-scope due to savior whitelisting, with Immunefi reversing its initial Medium severity recommendation to None without new technical justification.

RAI Reflexer Finance Immunefi CVE-2023-XXXXX
trust-security.xyz · Trust Security · 20 hours ago · details