All reports
highLogic errorEVM-Solidity

PoolTogether: Delegated amounts can be forcefully removed from anyone in the `TwabController`

Payout
$0
Protocol
PoolTogether
Disclosed
Aug 7, 2026
Source
code4rena

The PoolTogether vault contract contained a critical logic vulnerability in the sponsor function that allowed attackers to forcefully reset any user's delegation status. By calling the function with a zero deposit amount and a victim's address, an attacker cou …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.