mediumLogic errorEVM-Solidity
Debita Finance V3: Attacker will prevent lenders from canceling lend orders and block non-perpetual lend orders matching.
- Payout
- $0
- Protocol
- Debita Finance V3
- Disclosed
- Nov 25, 2024
- Source
- sherlock
The Debita Finance V3 lending protocol allowed canceled lend orders to be re-funded because DLOImplementation::addFunds never checked the order's isActive state. An attacker could alternate cancelOffer and addFunds on their own order to repeatedly decrement DL …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.