All reports
mediumLogic errorEVM-Solidity

PoolTogether: `TwabLib::getTwabBetween` can return inaccurate balances if `_startTime` and `_endTime` aren't safely bound

Payout
$0
Protocol
PoolTogether
Disclosed
Aug 7, 2026
Source
code4rena

A logic issue in PoolTogether's PrizePool contract allows TWAB balance queries to occur over unsafe time ranges. When PrizePool calculates user balances via _getVaultUserBalanceAndTotalSupplyTwab, it fails to execute the required isTimeRangeSafe check before i …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.