All reports
highReentrancyEVM-Solidity

Ammplify: All taker collateral and collected fees can be stolen by re-entering via `RFTLib.settle` to manipulate uniswap spot price when adding Maker liquidity

Payout
$0
Protocol
Ammplify
Disclosed
Sep 22, 2025
Source
sherlock

Ammplify's maker liquidity functions compute and charge a user token amounts for a new or adjusted Uniswap v3 position, but never verify the amounts the contract actually spends when the pool mints that liquidity. Because RFTLib.settle invokes a user-supplied …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.