All reports
mediumLogic errorEVM-Solidity

Yieldoor: `Vault::withdraw()` withdraws too much liquidity leading to idle capital and loss of fees

Payout
$0
Protocol
Yieldoor
Disclosed
Mar 3, 2025
Source
sherlock

Yieldoor's Vault.withdraw() computes a redeemer's owed amount as a proportional slice of the strategy's total balance and, whenever the idle balance is insufficient, unwinds that full amount from the LP position. It fails to subtract the idle capital already a …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.