All reports
mediumLogic errorEVM-Solidity

Axis Finance: Attacker can forbid users to get refunded if sends enough bids on the EMPAM module

Payout
$0
Protocol
Axis Finance
Disclosed
Mar 30, 2024
Source
sherlock

Axis Finance's EMPAM auction module had a gas-exhaustion denial-of-service flaw. The _refundBid function locates a requested bid by linearly scanning the entire encrypted-bid array before popping the entry, so an attacker who floods an auction with many minimu …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.