CVE-2020-35962: Loopring
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation.
Affected products
- Loopring Loopring: affected versions not specified
Published 2021-01-03. Last modified 2026-06-17.