mediumLogic errorEVM-Solidity
Yieldoor: `Vault::withdraw()` withdraws too much liquidity leading to idle capital and loss of fees
- Payout
- $0
- Protocol
- Yieldoor
- Disclosed
- Mar 3, 2025
- Source
- sherlock
Yieldoor's Vault.withdraw() computes a redeemer's owed amount as a proportional slice of the strategy's total balance and, whenever the idle balance is insufficient, unwinds that full amount from the LP position. It fails to subtract the idle capital already a …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.