All reports
mediumInteger overflow/underflowEVM-Solidity

Salty.IO: The user who withdraws liquidity from a particular pool is able to claim more rewards than they should by carefully selecting a `decreaseShareAmount` value such that the `virtualRewardsToRemove` is rounded down to zero

Payout
$0
Protocol
Salty.IO
Disclosed
Apr 19, 2024
Source
code4rena

Salty.IO's staking contract was vulnerable to an incentive extraction bug during liquidity withdrawal due to improper rounding in reward calculations. The protocol incorrectly performed integer division when determining the amount of virtual rewards to subtrac …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.