All reports
mediumLogic errorEVM-Solidity

LoopFi: Malicious actor can abuse the minimum shares check in `StakingLPEth` and cause DoS or locked funds for the last user that withdraws

Payout
$0
Protocol
LoopFi
Disclosed
Feb 17, 2025
Source
code4rena

LoopFi's `StakingLPEth` enforces a minimum total share supply (`MIN_SHARES`) via `_checkMinShares()` after every deposit and withdrawal to guard against inflation attacks. Because this check runs after the underlying share burn in `_withdraw`, an attacker can …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.