mediumInteger overflow/underflowEVM-Solidity
Salty.IO: The user who withdraws liquidity from a particular pool is able to claim more rewards than they should by carefully selecting a `decreaseShareAmount` value such that the `virtualRewardsToRemove` is rounded down to zero
- Payout
- $0
- Protocol
- Salty.IO
- Disclosed
- Apr 19, 2024
- Source
- code4rena
Salty.IO's staking contract was vulnerable to an incentive extraction bug during liquidity withdrawal due to improper rounding in reward calculations. The protocol incorrectly performed integer division when determining the amount of virtual rewards to subtrac …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-01-salty-findings/issues/1021
- https://github.com/code-423n4/2024-01-salty-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.