59386 sc high fund freeze from double stake subtraction when validator exits
Description
Brief / Intro
Vulnerability Details
if (
currentValidatorStatus == VALIDATOR_STATUS_EXITED ||
delegation.status == DelegationStatus.PENDING
) {
_updatePeriodEffectiveStake(..., false);
}Impact Details
Proof of Concept
Previous59361 sc high off by one in claimabledelegationperiods allows claimrewards to pay for periods after delegation end over claim theft of unclaimed yieldNext59411 sc insight inconsistency in migratetokenmanager in terms of the permitted caller
Was this helpful?