mediumFront-running / MEVEVM-Solidity
Collective: Since buyToken function has no slippage checking, users can get less tokens than expected when they buy tokens directly
- Payout
- $0
- Protocol
- Collective
- Disclosed
- Feb 8, 2024
- Source
- code4rena
The Collective protocol's buyToken function lacks slippage protection, exposing users to front-running attacks that result in receiving fewer tokens than anticipated. Because the protocol uses a Variable Rate Gradual Dutch Auction (VRGDA) that increases prices …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-12-revolutionprotocol-findings/issues/397
- https://github.com/code-423n4/2023-12-revolutionprotocol-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.