mediumLogic errorEVM-Solidity
Debita Finance V3: A borrower may pay more interest that he has specified, if orders are matched by a malicious actor
- Payout
- $0
- Protocol
- Debita Finance V3
- Disclosed
- Nov 25, 2024
- Source
- sherlock
Debita V3's DebitaV3Aggregator lets any caller match borrow and lend orders via matchOffersV3(), supplying up to 29 lend orders and a per-order principal amount. Because there is no minimum on lendAmountPerOrder and Solidity truncates integer division, a malic …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.