A security researcher discloses CVE-2026-4931, a critical integer truncation vulnerability in the Marginal V1 DeFi protocol that allowed complete liquidity drainage via a permissionless flash loan attack. The vulnerability stemmed from an unchecked uint128 cast in the adjust() function. The protocol paused within 48 hours and
Sort: