All reports
mediumInteger overflow/underflowEVM-Solidity

PoolTogether: Silent overflow could alter computation when calculating the `vaultPortion` in the `PrizePool` contract

Payout
$0
Protocol
PoolTogether
Disclosed
Aug 7, 2026
Source
code4rena

The PrizePool contract in the PoolTogether V5 protocol contains an unsafe type conversion flaw that can lead to silent integer overflows. During the calculation of a vault's portion of prizes, contribution metrics returned as uint256 are cast to int256 without …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.