All reports
highAccess controlEVM-Solidity

PoolTogether: `Vault.mintYieldFee` function can be called by anyone to mint `Vault Shares` to any recipient address

Payout
$0
Protocol
PoolTogether
Disclosed
Aug 7, 2026
Source
code4rena

The mintYieldFee function in the PoolTogether Vault contract contained a critical access control vulnerability that allowed unauthorized users to steal protocol-accrued yield fees. The function failed to restrict access to authorized callers and incorrectly al …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.