mediumLogic errorEVM-Solidity
Truflation: TrufVesting.cancelVesting calculates end of vesting incorrectly
- Payout
- $0
- Protocol
- Truflation
- Disclosed
- Jan 8, 2024
- Source
- sherlock
TrufVesting.cancelVesting is an owner-only function that stops a user's token vesting, but it incorrectly computes whether a vesting has already finished. The function's reverting check compares block.timestamp against startTime plus only the per-period token …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.