#42725 [SC-Critical] startUnstake() Reduces Total Supply, but StakingToken Balance in contract Remains Constant, Leading to Inflated accumulatedDeptRewardsYeet()
Description
Vulnerability Details
Impact Details
Recommendation:
Proof of Concept
Proof of Concept
Step 1: Staking Tokens
Step 2: Earning Rewards
Step 3: Initiating Unstake Without Actual Token Transfer
Step 4: Executing Reward Distribution
Step 5: Claiming Excessive Rewards
Previous#42723 [SC-Critical] Unstaked Tokens Included in Excess Reward Calculation Can Cause DoS for Unstaking UsersNext#42732 [SC-High] Incomplete token return whena user claim his rewards leads to rewards fund loss
Was this helpful?