All reports
mediumLogic errorOther

Karak: When malicious behavior occurs and DSS requests slashing against vault during 2 day period after `SLASHING_WINDOW` of 7 days is passed after staker initiates a withdrawal, token amount to be slashed is calculated to be higher than what it s…

Payout
$0
Protocol
Karak
Disclosed
Oct 7, 2024
Source
code4rena

A Karak slashing-accounting flaw lets a DSS over-slash a vault because the earmarked stake is computed from the vault's live totalAssets(), which still includes underlying tokens backing a staker withdrawal that has already passed the 7-day SLASHING_WINDOW and …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.