highOracle manipulationEVM-Solidity
NOYA: `_getPositionTVL` of `UNIv3Connector` wrongly assumes ownership of all liquidity of the provided ticks inside `positionManager`
- Payout
- $0
- Protocol
- NOYA
- Disclosed
- Feb 17, 2025
- Source
- code4rena
In NOYA's UNIv3Connector, the _getPositionTVL function computes a Uniswap V3 pool position key from the positionManager address and the tick bounds, then reads the aggregate liquidity for that key from the pool. Because the key is derived from the pool's posit …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-04-noya-findings/issues/708
- https://github.com/code-423n4/2024-04-noya-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.