tick-manipulation

1 article
sort: new top best
clear filter
0 7/10
vulnerability

Raydium's increase_liquidity function failed to validate whether remaining_accounts[0] was the correct TickArrayBitmapExtension account, allowing attackers to manipulate tick states and drain liquidity pools by bypassing intended price boundary checks. The whitehat discovered this critical flaw on January 10, 2024, and received a $505,000 bounty.

Raydium Immunefi @riproprip Solana Uniswap V3 increase_liquidity.rs TickArrayBitmapExtension
medium.com · riproprip · 18 hours ago · details