All reports
highLogic errorEVM-Solidity

PoolTogether: The Prize Layer for DeFi: Vault portion calculation in `PrizePool::getVaultPortion()` is incorrect as `_startDrawIdInclusive` has been erased

Payout
$0
Protocol
PoolTogether: The Prize Layer for DeFi
Disclosed
Jun 6, 2024
Source
sherlock

PoolTogether's PrizePool::getVaultPortion() derives vault prize shares from a draw range whose computed start draw id can point to a slot in the total-contribution circular buffer that has already been overwritten. Because the grand-prize estimated frequency r …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.