highLogic errorEVM-Solidity
Napier: Victim's fund can be stolen due to rounding error and exchange rate manipulation
- Payout
- $0
- Protocol
- Napier
- Disclosed
- Feb 26, 2024
- Source
- sherlock
Napier's BaseLSTAdapter added a ZeroShares guard to block the classic ERC4626 vault-inflation attack, but that guard is insufficient because the adapter derives totalAssets from the contract's raw WETH/stETH balance. An attacker can front-run a victim's first …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.