mediumReentrancyEVM-Solidity
Superfluid Locker System: An attacker may DoS user Fluid balance increases by frontrunning `FluidLocker::claim()` calls and calling `EP_PROGRAM_MANAGER::batchUpdateUserUnits()` directly
- Payout
- $0
- Protocol
- Superfluid Locker System
- Disclosed
- Nov 24, 2024
- Source
- sherlock
A griefing/front-running vulnerability in the Superfluid FluidLocker system lets an attacker spend a user's signed claim nonce in advance. FluidLocker::claim() first connects to the fluid pool and then calls EPProgramManager::updateUserUnits() to validate the …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.