All reports
highFlash loan attackEVM-Solidity

Maia DAO Ecosystem: A malicious user can front-run Gauges's call `addBribeFlywheel` to steal bribe rewards

Payout
$0
Protocol
Maia DAO Ecosystem
Disclosed
Sep 18, 2023
Source
code4rena

An uninitialized `endCycle` state variable in `FlywheelAcummulatedRewards` allows users to claim bribe rewards immediately upon adding a flywheel to a gauge. An attacker can front-run the `addBribeFlywheel` transaction by depositing gauge tokens (`incrementGau …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.