twap-oracle-missing

1 article
sort: new top best
clear filter
0 8/10
vulnerability

Tokemak's liquidity controllers are vulnerable to token theft via pool ratio manipulation. An attacker with ADD_LIQUIDITY_ROLE can plant a malicious Uniswap/Sushi pair with an extreme token ratio, then trigger the deploy() function to cause the controller to deposit funds at that manipulated ratio, losing up to 100% of reserves through subsequent swaps exploiting the constant product formula.

Tokemak SushiswapControllerV2 UniswapController FOX ALCX Chainlink
trust-security.xyz · Trust · 17 hours ago · details