Canto Dex Oracle contest - JansenC's results

Execution layer for original work.

General Information

Platform: Code4rena

Start Date: 07/09/2022

Pot Size: $20,000 CANTO

Total HM: 7

Participants: 65

Period: 1 day

Judge: 0xean

Total Solo HM: 3

Id: 159

League: ETH

Canto

Findings Distribution

Researcher Performance

Rank: 59/65

Findings: 1

Award: $39.22

🌟 Selected for report: 0

🚀 Solo Findings: 0

Awards

242.8216 CANTO - $39.22

Labels

bug
QA (Quality Assurance)
sponsor disputed
edited-by-warden

External Links

#0 - nivasan1

2022-09-09T23:59:11Z

In each of these cases, the numerator in divisions are either scaled by 1e18 before the division, or the numerator is a product of two values scaled by 1e18. In either case, the final division is un-scales the numerator. In other cases, cubing a value that is scaled by 1e18 opens the possibilities for overflows with values that are very likely, as such, it is worth having some integer truncation in this arithmetic, as opposed to risking overflows.

#1 - 0xean

2022-09-14T18:46:40Z

Warden fails to show impact of this issue and therefore I do not believe this issue can be judged to be medium risk without a clear impact of it leading to the following

2 — Med: Assets not at direct risk, but the function of the protocol or its availability could be impacted, or leak value with a hypothetical attack path with stated assumptions, but external requirements.

downgrading to QA

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter