All reports
mediumLogic errorEVM-Solidity

Mellow Flexible Vaults: Malicious Users Can Perpetually Lock `feeRecipient` Shares via Targeted Lockup Reset

Payout
$0
Protocol
Mellow Flexible Vaults
Disclosed
Jul 28, 2025
Source
sherlock

Mellow Flexible Vaults mints fee shares to the feeRecipient during deposits, redemptions, and protocol fee collection, but ShareManager.mint applies the configured targetLockup to every recipient, including the feeRecipient. Because the lockedUntil timestamp r …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.