highLogic errorEVM-Solidity
Rubicon: DOS of market operations with malicious offers
- Payout
- $0
- Protocol
- Rubicon
- Disclosed
- Feb 17, 2025
- Source
- code4rena
Rubicon's orderbook fills trades by repeatedly pulling the best-priced offer from a price-sorted linked list inside buyAllAmount/sellAllAmount, but the offer() entry point never validates the owner or recipient addresses. A malicious maker can post a small, ag …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-04-rubicon-findings/issues/644
- https://github.com/code-423n4/2023-04-rubicon-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.