highLogic errorEVM-Solidity
Autonomint Colored Dollar V1: Malicious users can DOS the protocol by setting downsideProtected to a large value
- Payout
- $0
- Protocol
- Autonomint Colored Dollar V1
- Disclosed
- Dec 30, 2024
- Source
- sherlock
CDS.sol exposes updateDownsideProtected() as a permissionless external function that merely adds its argument to the downsideProtected state variable. An attacker can inflate downsideProtected beyond totalCdsDepositedAmount, and because _updateCurrentTotalCdsD …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.