mediumFront-running / MEVEVM-Solidity
Paladin: Possible to grief and prevent all users from claiming via front-running `multiClaim()` calls
- Payout
- $0
- Protocol
- Paladin
- Disclosed
- Feb 7, 2024
- Source
- hats
Paladin's MultiMerkleDistributorV2 lets any address claim quest rewards on behalf of any account provided it supplies a valid merkle proof. An attacker can monitor the mempool for a victim's multiClaim() or claimQuest() transaction, copy the victim's last clai …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Paladin-0x1610bfde27e57b068af7f38aec3d2a7b1d146989/issues/18
- https://github.com/hats-finance/Paladin-0x1610bfde27e57b068af7f38aec3d2a7b1d146989
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.