yield-farming

1 article
Sort: New Top Best
clear filter
0 9/10
vulnerability

A vulnerability in Tranchess's ShareStaking contract allows attackers to drain user funds by exploiting a skipped `_checkpoint()` call during rebalance events, causing a mismatch between token total supplies and actual contract balances. The attack leverages the contract's gas optimization technique to manipulate `spareAmount` calculations and steal staked tokens.

Tranchess ShareStaking FundV3 Immunefi Queen Bishop Rook floranguyen0
github.com · Flora · 4 hours ago · details