highLogic errorEVM-Solidity
Cork Protocol: Attackers will steal the reserve from the `Vault` by receiving `ra` in `FlashSwapRouter::__swapDsforRa()`
- Payout
- $0
- Protocol
- Cork Protocol
- Disclosed
- Sep 10, 2024
- Source
- sherlock
Cork Protocol's FlashSwapRouter misroutes reserve assets during the DS-for-RA flash-swap sell path. When a user calls swapRaforDs() and the reserve is sold, the internal __swapDsforRa() helper runs a UniswapV2-style flash swap whose uniswapV2Call callback deco …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.