Ondo Finance - DanielArmstrong's results

Institutional-Grade Finance, Now Onchain.

General Information

Platform: Code4rena

Start Date: 29/03/2024

Pot Size: $36,500 USDC

Total HM: 5

Participants: 72

Period: 5 days

Judge: 3docSec

Total Solo HM: 1

Id: 357

League: ETH

Ondo Finance

Findings Distribution

Researcher Performance

Rank: 57/72

Findings: 1

Award: $8.28

🌟 Selected for report: 0

🚀 Solo Findings: 0

Lines of code

https://github.com/code-423n4/2024-03-ondo-finance/blob/main/contracts/ousg/ousgInstantManager.sol#L230

Vulnerability details

Impact

When a user's transaction is delayed for long time because of rising of gas price or other reason, the user can lose funds unexpectedly. This vulnerability can make users to suffer from price manipulation attack.

Proof of Concept

There is no slippage check in ousgInstantManager.sol#mint, redeem.

Tools Used

Manual Review

We have to add slippage check in ousgInstantManager.sol#mint, redeem.

Assessed type

MEV

#0 - c4-pre-sort

2024-04-04T02:59:00Z

0xRobocop marked the issue as duplicate of #250

#1 - c4-pre-sort

2024-04-04T22:59:55Z

0xRobocop marked the issue as duplicate of #156

#2 - c4-judge

2024-04-09T08:00:58Z

3docSec marked the issue as satisfactory

#3 - 3docSec

2024-04-11T07:09:06Z

Does not cover the mintRebasing and redeemRebasing functions -> 50%

#4 - c4-judge

2024-04-11T07:09:10Z

3docSec marked the issue as partial-50

#5 - c4-judge

2024-04-11T15:13:13Z

3docSec changed the severity to QA (Quality Assurance)

#6 - c4-judge

2024-04-11T15:16:12Z

3docSec marked the issue as grade-b

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter