mediumLogic errorEVM-Solidity
Size: Size uses wrong source to query available liquidity on Aave, resulting in borrow and lend operations being bricked upon mainnet deployment
- Payout
- $0
- Protocol
- Size
- Disclosed
- Sep 16, 2024
- Source
- code4rena
Size's CapsLibrary.validateVariablePoolHasEnoughLiquidity checks available variable-pool liquidity by reading the underlyingBorrowToken balance of the Aave variablePool contract address. On live Aave v3 deployments all supplied liquidity is actually held in th …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-06-size-findings/issues/218
- https://github.com/code-423n4/2024-06-size-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.