All reports
mediumLogic errorOther

Metric: A permissionless swapper will extract principal from exact-share liquidity providers

Payout
$0
Protocol
Metric
Disclosed
Jul 27, 2026
Source
sherlock

Metric's exact-input in-bin swap functions (buyToken0InBinSpecifiedIn and buyToken1InBinSpecifiedIn) round a small expected output to zero while still advancing the active-bin cursor to the attacker-chosen target position, leaving both bin reserves and fee acc …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.