highLogic errorOther
HydraDX: An attacker possesses the capability to exhaust the entirety of liquidity within the stable swap pools by manipulating the buy function, specifically by setting the `asset_in` parameter equal to the `asset_out` parameter
- Payout
- $0
- Protocol
- HydraDX
- Disclosed
- Apr 10, 2024
- Source
- code4rena
HydraDX's Stableswap pallet `buy()` extrinsic accepted identical `asset_in` and `asset_out` values without validation. When both are equal, the underlying `calculate_in_given_out` math derives a new reserve identical to the old one, so the computed input amoun …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-02-hydradx-findings/issues/58
- https://github.com/code-423n4/2024-02-hydradx-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.