highLogic errorEVM-Solidity
Kintsu: KIN-H02: Malicious users can prevent other users from redeeming rewards by manipulating `total_pooled` with duplicate withdrawal requests
- Payout
- $0
- Protocol
- Kintsu
- Disclosed
- May 17, 2024
- Source
- hats
Kintsu's AZERO staking vault lets users request token unlocks and later batch-redeem them through send_batch_unlock_requests, which decrements the global total_pooled once per submitted batch id. The function rejects batch ids that were already unlocked but do …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Kintsu-0x7d70f9442af3a9a0a734fa6a1b4857f25518e9d2/issues/28
- https://github.com/hats-finance/Kintsu-0x7d70f9442af3a9a0a734fa6a1b4857f25518e9d2
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.