mediumLogic errorEVM-Solidity
Burve: Incorrect earnings calculation in `removeValueSingle()` function causes partial user losses
- Payout
- $0
- Protocol
- Burve
- Disclosed
- May 7, 2025
- Source
- sherlock
In Burve's `removeValueSingle()` path, the asset-level `remove()`/`collect()` runs before the closure's `removeValueSingle()`/`trimBalance()` updates the earnings-per-value accumulator. The removal therefore computes the user's collected earnings from a stale …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.