All reports
mediumInteger overflow/underflowEVM-Solidity

PoolTogether: `PrizeVault.maxDeposit()` doesn't take into account produced fees

Payout
$0
Protocol
PoolTogether
Disclosed
Apr 4, 2024
Source
code4rena

The PrizeVault contract incorrectly calculates the maximum allowed deposit amount by failing to account for reserved yield fees. When a user deposits the full amount permitted by maxDeposit, the vault's liquidity is fully utilized, preventing fee recipients fr …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.