mediumLogic errorEVM-Solidity
Burve: User can backrun an admin calling `setEX128` and steal the difference in tokens
- Payout
- $0
- Protocol
- Burve
- Disclosed
- May 7, 2025
- Source
- sherlock
Burve's bonding-curve pricing derives each token's value from an efficiency factor eX128, with the pool invariant that the summed token value equals target*n. When the pool owner alters eX128 for a token via setEX128, the contract never recomputes targetX128, …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.