CIP#29 - Fix potential vulnerability on changing A down in old pools

Summary:

A fix for a vulnerability reported by Peter Zeitz is deployed and ready to be executed. The idea is to limit the imbalance when the parameter change can be applied.

You can read about the vulnerability there: https://medium.com/@peter_4205/curve-vulnerability-report-a1d7630140ec

You can find the fix at this address: https://github.com/curvefi/curve-dao-contracts/pull/44

Specification:

https://github.com/curvefi/curve-dao-contracts/pull/44

Poll:

https://dao.curve.fi/vote/ownership/22

1 Like

Quorum is 30% so please go vote!

1 Like