All reports
mediumLogic errorEVM-Solidity

MagicSea - the native DEX on the IotaEVM: Voting and bribe rewards can be hijacked during emergency unlock by already existing positions

Payout
$0
Protocol
MagicSea - the native DEX on the IotaEVM
Disclosed
Jul 11, 2024
Source
sherlock

MagicSea's staking contract permits existing NFT positions to call addToPosition() during an active emergency unlock, while renewLock(), extendLock(), and createPosition() are all blocked or rendered unusable in that window. An attacker who pre-opens many mini …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.