mediumLogic errorEVM-Solidity
PoolTogether: The Prize Layer for DeFi: `drawTimeoutAt()` causes the prize pool to shutdown one draw earlier
- Payout
- $0
- Protocol
- PoolTogether: The Prize Layer for DeFi
- Disclosed
- Jun 6, 2024
- Source
- sherlock
PoolTogether's PrizePool computes its shutdown deadline with an off-by-one error: drawTimeoutAt() returns the close time of draw _lastAwardedDrawId + drawTimeout, yet awardDraw() only allows awarding a draw after that draw has closed. The mismatch means the po …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.