Mimo DeFi contest - AlleyCat's results

Bridging the chasm between the DeFi world and the world of regulated financial institutions.

General Information

Platform: Code4rena

Start Date: 28/04/2022

Pot Size: $50,000 USDC

Total HM: 7

Participants: 43

Period: 5 days

Judge: gzeon

Total Solo HM: 2

Id: 115

League: ETH

Mimo DeFi

Findings Distribution

Researcher Performance

Rank: 4/43

Findings: 2

Award: $4,235.13

🌟 Selected for report: 1

🚀 Solo Findings: 1

Findings Information

🌟 Selected for report: AlleyCat

Labels

bug
2 (Med Risk)
sponsor acknowledged

Awards

4146.0865 USDC - $4,146.09

External Links

Lines of code

https://github.com/code-423n4/2022-04-mimo/blob/main/core/contracts/libraries/ABDKMath64x64.sol#L626 https://github.com/code-423n4/2022-04-mimo/blob/main/core/contracts/libraries/ABDKMath64x64.sol#L629 https://github.com/code-423n4/2022-04-mimo/blob/main/core/contracts/libraries/ABDKMath64x64.sol#L630

Vulnerability details

Impact

Solidity could truncate the results, performing multiplication before division will prevent rounding/truncation in solidity math.

Consider ordering multiplication first.

Awards

89.0354 USDC - $89.04

Labels

bug
QA (Quality Assurance)

External Links

BalancerV2LPOracle._getNormalizedBalance shadows: - BalancerV2LPOracle.decimals (contracts/oracles/BalancerV2LPOracle.sol#19 - AggregatorV3Interface.decimals() (contracts/chainlink/AggregatorV3Interface.sol#6

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter