Skip to content

Security patch — Cantina contest 2025-07-14 - #119

Closed
azat-hafizov wants to merge 11 commits into
release/cantinafrom
develop
Closed

Security patch — Cantina contest 2025-07-14#119
azat-hafizov wants to merge 11 commits into
release/cantinafrom
develop

Conversation

@azat-hafizov

@azat-hafizov azat-hafizov commented Aug 25, 2025

Copy link
Copy Markdown
Collaborator

Findings fixed in PR (code changes)

  • C478 Value Leak in rebase and distributionLoss calculation: 5aabf29
  • C322 Dynamic fee calculation with incorrect parameter: 500d7bc
  • C128 User can avoid redeemFee by calling redeemMulti: b6eba2f
  • C524 _syncTotalSupply uses stale balances to update total supply: 9bd719c
  • C441 donateD Does Not Reduce Buffer Bad Debt: 4ee1bfc
  • C326 No syncRamping modifier in the rebase function: b42c750

Findings acknowledged

  • C505 Fee Extraction Is Possible Via MEV Sandwich Attack
  • C206 Flawed Order of Operations Leads to Mint Fee Rebate
  • C475 Self Pegging Asset Contract will be DOS’d when any of the Asset Token Value is Zero

Backwards compatibility

  • No storage layout changes

Artifacts

Diff link: release/cantina...develop

@zakrad
zakrad self-requested a review August 25, 2025 05:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants