Canto Liquidity Mining Protocol - IceBear's results

Execution layer for original work.

General Information

Platform: Code4rena

Start Date: 03/10/2023

Pot Size: $24,500 USDC

Total HM: 6

Participants: 62

Period: 3 days

Judge: LSDan

Total Solo HM: 3

Id: 288

League: ETH

Canto

Findings Distribution

Researcher Performance

Rank: 43/62

Findings: 1

Award: $4.94

QA:
grade-b

🌟 Selected for report: 0

🚀 Solo Findings: 0

Awards

4.9369 USDC - $4.94

Labels

bug
downgraded by judge
grade-b
QA (Quality Assurance)
sufficient quality report
duplicate-81
Q-31

External Links

Lines of code

https://github.com/code-423n4/2023-10-canto/blob/main/canto_ambient/contracts/callpaths/LiquidityMiningPath.sol#L65 https://github.com/code-423n4/2023-10-canto/blob/main/canto_ambient/contracts/callpaths/LiquidityMiningPath.sol#L74

Vulnerability details

Impact

The setConcRewards() and setAmbRewards() functions are public functions that lack checks on weekFrom and weekTo, allowing anyone to set past dates.

Proof of Concept

https://github.com/code-423n4/2023-10-canto/blob/main/canto_ambient/contracts/callpaths/LiquidityMiningPath.sol#L65

https://github.com/code-423n4/2023-10-canto/blob/main/canto_ambient/contracts/callpaths/LiquidityMiningPath.sol#L74

Tools Used

Ensure that weekFrom is greater than or equal to block.timestamp.

Assessed type

Timing

#0 - c4-pre-sort

2023-10-07T13:24:17Z

141345 marked the issue as duplicate of #4

#1 - c4-pre-sort

2023-10-07T13:37:04Z

141345 marked the issue as not a duplicate

#2 - c4-pre-sort

2023-10-07T13:37:12Z

141345 marked the issue as duplicate of #81

#3 - c4-pre-sort

2023-10-09T16:13:44Z

141345 marked the issue as sufficient quality report

#4 - c4-judge

2023-10-18T20:49:30Z

dmvt changed the severity to QA (Quality Assurance)

#5 - c4-judge

2023-10-18T22:40:16Z

dmvt marked the issue as grade-b

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter