Security Audit Flags Critical Reentrancy and Access-Control Flaws in Gemini DeFi Protocol
A security audit conducted between October 1 and October 21, 2024, on Gemini, a cross-chain DeFi protocol with approximately $5.65 billion in total value locked, identified ten vulnerabilities across its core smart contracts. Auditors found two critical and two high-severity reentrancy flaws, along with one critical and three high-severity access-control weaknesses. The most serious issue involves GeminiVault's withdrawal function, which transfers tokens before updating internal balances, making it exploitable via malicious ERC-777 token callbacks for potential losses exceeding $500 million. A second critical flaw exposes the protocol's fee-recipient admin function to a single-point-of-failure takeover due to insufficient role-based access controls. The overall risk score was rated 8 out of 10, though auditors noted that fixes can be implemented with minimal gas overhead.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in