All reports
highLogic errorEVM-Solidity

Autonomint Colored Dollar V1: Malicious users can DOS the protocol by setting downsideProtected to a large value

Payout
$0
Protocol
Autonomint Colored Dollar V1
Disclosed
Dec 30, 2024
Source
sherlock

CDS.sol exposes updateDownsideProtected() as a permissionless external function that merely adds its argument to the downsideProtected state variable. An attacker can inflate downsideProtected beyond totalCdsDepositedAmount, and because _updateCurrentTotalCdsD …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.