Badger-Vested-Aura contest - 242's results

Bringing BTC to DeFi

General Information

Platform: Code4rena

Start Date: 15/06/2022

Pot Size: $30,000 USDC

Total HM: 5

Participants: 55

Period: 3 days

Judge: Jack the Pug

Id: 138

League: ETH

BadgerDAO

Findings Distribution

Researcher Performance

Rank: 40/55

Findings: 1

Award: $51.26

🌟 Selected for report: 0

🚀 Solo Findings: 0

Awards

51.2645 USDC - $51.26

Labels

bug
QA (Quality Assurance)
sponsor acknowledged
valid

External Links

LOW-01: When contract in a paused state, process expired locks can still be executed due to missing modifier

link: https://github.com/Badger-Finance/vested-aura/blob/v0.0.2/contracts/MyStrategy.sol#L391= MyStrategy.sol:L391 - function performUpkeep can execute external call: LOCKER.processExpiredLocks(false); even if contract has been set paused, due to lack of whenNotPaused modifier.

Fix: Consider adding whenNotPaused modifier to performUpkeep to prevent it from being executed when contract is paused.

#0 - GalloDaSballo

2022-06-19T01:55:03Z

Ack

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter