mediumLogic errorEVM-Solidity
Paladin: Loot.sol - Updating the vestingDuration with active vests can lead to unexpected slashing
- Payout
- $0
- Protocol
- Paladin
- Disclosed
- Feb 7, 2024
- Source
- hats
Paladin's Loot.sol exposes an owner-controlled updateVestingDuration function that mutates a protocol-wide vesting window which is read at claim execution time rather than snapshotted when a user's loot is created. Because the effective vesting duration is eva …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Paladin-0x1610bfde27e57b068af7f38aec3d2a7b1d146989/issues/5
- https://github.com/hats-finance/Paladin-0x1610bfde27e57b068af7f38aec3d2a7b1d146989
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.