Sublime contest - 0x1f8b's results

Democratizing credit via Web3.

General Information

Platform: Code4rena

Start Date: 09/12/2021

Pot Size: $50,000 USDC

Total HM: 19

Participants: 21

Period: 7 days

Judge: 0xean

Total Solo HM: 14

Id: 61

League: ETH

Sublime

Findings Distribution

Researcher Performance

Rank: 9/21

Findings: 3

Award: $1,690.45

🌟 Selected for report: 5

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: WatchPug

Also found by: 0x1f8b

Labels

bug
duplicate
3 (High Risk)

Awards

1267.5392 USDC - $1,267.54

External Links

Handle

0x1f8b

Vulnerability details

Impact

The contract doesn't work as expected.

Proof of Concept

The method, emergencyWithdraw inside the contract yield/NoYield doesn't work as expected, the transfer was done with received value, and it should be done with amount, so the emergencyWithdraw never will work, always it will send 0 tokens.

Tools Used

Manual review

Fix to send the amount:

  • IERC20(_asset).safeTransfer(_wallet, amount);

#0 - ritik99

2021-12-27T05:16:07Z

Duplicate of #115

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter