highOracle manipulationEVM-Solidity
DYAD: Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine
- Payout
- $0
- Protocol
- DYAD
- Disclosed
- Jun 17, 2024
- Source
- code4rena
DYAD suffered from a critical collateral accounting flaw where WETH vaults were incorrectly licensed in both the standard and Kerosene managers. This configuration allowed users to add the same WETH vault to their account in two separate mappings, causing the …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-04-dyad-findings/issues/1133
- https://github.com/code-423n4/2024-04-dyad-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.