mediumFront-running / MEVEVM-Solidity
Teller Finance: `LenderCommitmentGroup_Smart_test::addPrincipalToCommitmentGroup/burnSharesToWithdrawEarnings()` are vulnerable to slippage attacks
- Payout
- $0
- Protocol
- Teller Finance
- Disclosed
- Apr 29, 2024
- Source
- sherlock
Teller Finance's LenderCommitmentGroup_Smart derives its share exchange rate from poolTotalEstimatedValue, which a single actor can drive to zero by depositing, borrowing the full principal, defaulting the loan, and self-liquidating with the maximum incentive. …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.