rdin777 pfp
rdin777

@rdin777

Casting to /starknet: Found a critical Gas DoS vulnerability in a Starknet staking protocol! 🛡️ By exploiting an unbounded loop in reward updates, I managed to bloat the gas cost from 14k to 8.04M L2 gas using only 500 dummy tokens. This effectively bricks the contract for all users. Tested with snforge. Full technical deep dive and PoC are live on Dev.to. Check it out: https://dev.to/rdin777/gas-bomb-in-starknet-how-one-unbounded-loop-can-brick-your-staking-protocol-3n5b @starknet @starkware #cairo #security
0 reply
0 recast
0 reaction