All reports
highLogic errorEVM-Solidity

Cork Protocol: FlashSwapRouter::emptyReserve() and FlashSwapROuter::emptyReservePartial() functions return incorrect values

Payout
$0
Protocol
Cork Protocol
Disclosed
Sep 10, 2024
Source
sherlock

Cork's FlashSwapRouter reserve helpers incorrectly return the reserve that remains after the emptied amount is subtracted, instead of the amount actually emptied. This mis-sizes redemptions in two normal-operation paths. In the new-issuance flow, _liquidatedLp …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.