All reports
highLogic errorEVM-Solidity

BMX Deli Swap: In the `IncentiveGauge._upsertIncentive()` function, `_updatePoolByPid()` should be called outside the `if` statement

Payout
$0
Protocol
BMX Deli Swap
Disclosed
Sep 16, 2025
Source
sherlock

In BMX Deli Swap's IncentiveGauge, _upsertIncentive() only refreshes pool accounting when the pool already has an active reward rate, so applying a fresh incentive to a pool whose rewardRate is zero leaves the pool's lastUpdated timestamp stale even though the …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.