CVE-2018-11687: Bitcoin Red Project Bitcoin Red
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
An integer overflow in the distributeBTR function of a smart contract implementation for Bitcoin Red (BTCR), an Ethereum ERC20 token, allows the owner to accomplish an unauthorized increase of digital assets by providing a large address[] array, as exploited in the wild in May 2018, aka the "ownerUnderflow" issue.
Affected products
- Bitcoin Red Project Bitcoin Red: affected versions not specified
Published 2018-08-15. Last modified 2026-06-17.