All reports
highLogic errorEVM-Solidity

Napier: Victim's fund can be stolen due to rounding error and exchange rate manipulation

Payout
$0
Protocol
Napier
Disclosed
Feb 26, 2024
Source
sherlock

Napier's BaseLSTAdapter added a ZeroShares guard to block the classic ERC4626 vault-inflation attack, but that guard is insufficient because the adapter derives totalAssets from the contract's raw WETH/stETH balance. An attacker can front-run a victim's first …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.