All reports
mediumLogic errorEVM-Solidity

Burve: User can backrun an admin calling `setEX128` and steal the difference in tokens

Payout
$0
Protocol
Burve
Disclosed
May 7, 2025
Source
sherlock

Burve's bonding-curve pricing derives each token's value from an efficiency factor eX128, with the pool invariant that the summed token value equals target*n. When the pool owner alters eX128 for a token via setEX128, the contract never recomputes targetX128, …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.