highLogic errorEVM-Solidity
Canto: update_market() nextEpoch calculation incorrect
- Payout
- $0
- Protocol
- Canto
- Disclosed
- Feb 7, 2024
- Source
- code4rena
Canto's LendingLedger.update_market() accrues per-share rewards by walking epoch segments, but derives the segment boundary from the loop iterator rather than the epoch anchor. When an update call spans an epoch boundary and the newer epoch has a lower or zero …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-01-canto-findings/issues/9
- https://github.com/code-423n4/2024-01-canto-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.