token-balance-manipulation

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A critical logic error in Yield Protocol's strategy contract allowed attackers to drain pool tokens by inflating the balance calculation through direct token transfers; the vulnerability was responsibly disclosed by whitehat Paludo0x, who received a $95,000 USDC bounty after the $950k at-risk vulnerability was patched by modifying the burn function to use cached pool values instead of live balance checks.

Yield Protocol Immunefi Paludo0x YieldSpace Pool fyToken Foundry
medium.com · Paludo0x · 18 hours ago · details