highGovernance attackEVM-Solidity
Ethereum Credit Guild: The `userGaugeProfitIndex` is not set correctly, allowing an attacker to receive rewards without waiting
- Payout
- $0
- Protocol
- Ethereum Credit Guild
- Disclosed
- Feb 22, 2024
- Source
- code4rena
A logic vulnerability in Ethereum Credit Guild's ProfitManager contract allows attackers to claim unearned gauge rewards immediately after voting. When claimGaugeRewards is called during initial gauge voting, an early return check prevents userGaugeProfitIndex …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-12-ethereumcreditguild-findings/issues/1194
- https://github.com/code-423n4/2023-12-ethereumcreditguild-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.