All reports
mediumLogic errorEVM-Solidity

Truflation: TrufVesting.cancelVesting calculates end of vesting incorrectly

Payout
$0
Protocol
Truflation
Disclosed
Jan 8, 2024
Source
sherlock

TrufVesting.cancelVesting is an owner-only function that stops a user's token vesting, but it incorrectly computes whether a vesting has already finished. The function's reverting check compares block.timestamp against startTime plus only the per-period token …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.