All reports
mediumLogic errorEVM-Solidity

Ammplify: An attacker can block a user from opening new Maker/Taker positions by “donating” 16 unwanted Maker assets, saturating their asset quota

Payout
$0
Protocol
Ammplify
Disclosed
Sep 22, 2025
Source
sherlock

Ammplify's MakerFacet allows anyone to call newMaker() with an arbitrary recipient, minting an asset token straight into another address's per-owner quota without consent. Because Maker and Taker assets share a single quota capped at MAX_ASSETS_PER_OWNER = 16, …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.