mediumLogic errorEVM-Solidity
Ammplify: transferVaultBalance function is unusable and mistransfers user's funds due to hardcoded asset ID
- Payout
- $0
- Protocol
- Ammplify
- Disclosed
- Sep 22, 2025
- Source
- sherlock
Ammplify's admin vault-migration function, AdminFacet.transferVaultBalance, hardcodes TAKER_VAULT_ID (80085) and forwards it to VaultLib.transfer as the userId for both the source withdrawal and destination deposit. Because taker and view balances are keyed by …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.