All reports
mediumFront-running / MEVEVM-Solidity

PoolTogether: `Claimer.claimPrizes` can be front-runned in order to make losses for the claim bot

Payout
$0
Protocol
PoolTogether
Disclosed
Aug 7, 2026
Source
code4rena

The PoolTogether V5 prize-claiming mechanism was vulnerable to front-running, where malicious actors could cause large batch-claim transactions from automated bots to revert entirely. By claiming a single prize ahead of a bot's batched transaction, attackers e …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.