FEI and TRIBE Redemption contest - Picodes's results

A new DeFi primitive that allows any token to become productive and provide FEI liquidity at no cost to the markets that need it most.

General Information

Platform: Code4rena

Start Date: 09/09/2022

Pot Size: $42,000 USDC

Total HM: 2

Participants: 101

Period: 3 days

Judge: hickuphh3

Total Solo HM: 2

Id: 161

League: ETH

Tribe

Findings Distribution

Researcher Performance

Rank: 30/101

Findings: 1

Award: $33.67

🌟 Selected for report: 0

🚀 Solo Findings: 0

[NC - 01] - Incorrect comment

https://github.com/code-423n4/2022-09-tribe/blob/769b0586b4975270b669d7d1581aa5672d6999d5/contracts/shutdown/fuse/MultiMerkleRedeemer.sol#L48

“The amount of cTokens a user in their claim” -> “The amount of cTokens a user has in their claim” ?

[NC - 02] - MESSAGE_HASH could be constant

In MultiMerkleRedeemer, MESSAGE is constant but MESSAGE_HASH is not, which looks like an incoherence.

https://github.com/code-423n4/2022-09-tribe/blob/769b0586b4975270b669d7d1581aa5672d6999d5/contracts/shutdown/fuse/MultiMerkleRedeemer.sol#L56

[NC - 03] - MultiMerkleRedeemer only works for EOA MultiMerkleRedeemer: How do you intend to handle all the multisig and other contracts ?

[NC - 04] - Typo

“User provides the the cToken” -> “User provides the cToken”

https://github.com/code-423n4/2022-09-tribe/blob/769b0586b4975270b669d7d1581aa5672d6999d5/contracts/shutdown/fuse/RariMerkleRedeemer.sol#L163

#0 - HickupHH3

2022-10-08T08:23:49Z

NC-03: see #54

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter