All reports
highLogic errorEVM-Solidity

MagicSea - the native DEX on the IotaEVM: Attacker can block all votes to a specific pool by triggering an overflow error

Payout
$0
Protocol
MagicSea - the native DEX on the IotaEVM
Disclosed
Jul 11, 2024
Source
sherlock

MagicSea's permissionless bribe-rewarder design lets anyone attach a BribeRewarder funded with an arbitrary token to any pool. An attacker mints close to type(uint256).max of a custom token, schedules it as a single-period bribe, and casts a 1-wei vote to push …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.