All reports
highLogic errorOther

HydraDX: An attacker possesses the capability to exhaust the entirety of liquidity within the stable swap pools by manipulating the buy function, specifically by setting the `asset_in` parameter equal to the `asset_out` parameter

Payout
$0
Protocol
HydraDX
Disclosed
Apr 10, 2024
Source
code4rena

HydraDX's Stableswap pallet `buy()` extrinsic accepted identical `asset_in` and `asset_out` values without validation. When both are equal, the underlying `calculate_in_given_out` math derives a new reserve identical to the old one, so the computed input amoun …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.