All reports
mediumLogic errorEVM-Solidity

Debita Finance V3: Attacker will prevent lenders from canceling lend orders and block non-perpetual lend orders matching.

Payout
$0
Protocol
Debita Finance V3
Disclosed
Nov 25, 2024
Source
sherlock

The Debita Finance V3 lending protocol allowed canceled lend orders to be re-funded because DLOImplementation::addFunds never checked the order's isActive state. An attacker could alternate cancelOffer and addFunds on their own order to repeatedly decrement DL …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.