mediumOracle manipulationEVM-Solidity
Revert Lend: Large decimal of `referenceToken` causes overflow at oracle price calculation
- Payout
- $0
- Protocol
- Revert Lend
- Disclosed
- May 22, 2024
- Source
- code4rena
The V3Oracle contract in Revert Lend incorrectly structures its arithmetic for normalizing Chainlink price feeds, leading to integer overflows when handling tokens with 18 decimals. By multiplying large powers of 10 with price data in Q96 format within a singl …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-03-revert-lend-findings/issues/409
- https://github.com/code-423n4/2024-03-revert-lend-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.