mediumFront-running / MEVEVM-Solidity
PoolTogether: `Claimer.claimPrizes` can be front-runned in order to make losses for the claim bot
- Payout
- $0
- Protocol
- PoolTogether
- Disclosed
- Aug 7, 2026
- Source
- code4rena
The PoolTogether V5 prize-claiming mechanism was vulnerable to front-running, where malicious actors could cause large batch-claim transactions from automated bots to revert entirely. By claiming a single prize ahead of a bot's batched transaction, attackers e …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-07-pooltogether-findings/issues/115
- https://github.com/code-423n4/2023-07-pooltogether-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.