Skip to content

Latest commit

 

History

History
9 lines (5 loc) · 470 Bytes

003.md

File metadata and controls

9 lines (5 loc) · 470 Bytes

First Depositor Can Steal Funds From Vault

Summary

The protocol had a vault that was missing key checks, allowing an attacker to front-run the first user to deposit on a new vault and cause their received shares to be zero for a non-zero amount, while the attacker had 1 share. The attacker could then use this 1 share to withdraw all funds from the vault, including those of the other user.

Conclusion

The Protocol quickly confirmed and fixed the issue.