highFront-running / MEVEVM-Solidity
Thorchain: A malicious user can steal money out of the vault and other users
- Payout
- $0
- Protocol
- Thorchain
- Disclosed
- Aug 5, 2024
- Source
- code4rena
The THORChain router protocol is vulnerable to fund theft when interacting with rebasing tokens such as AMPL due to incorrect accounting of token balances. The protocol relies on fixed allowance values recorded at the time of deposit; however, rebasing tokens …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-06-thorchain-findings/issues/85
- https://github.com/code-423n4/2024-06-thorchain-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.