Fraxlend (Frax Finance) contest - The_GUILD's results

Fraxlend: A permissionless lending platform and the final piece of the Frax Finance Defi Trinity.

General Information

Platform: Code4rena

Start Date: 12/08/2022

Pot Size: $50,000 USDC

Total HM: 15

Participants: 120

Period: 5 days

Judge: Justin Goro

Total Solo HM: 6

Id: 153

League: ETH

Frax Finance

Findings Distribution

Researcher Performance

Rank: 89/120

Findings: 1

Award: $45.83

๐ŸŒŸ Selected for report: 0

๐Ÿš€ Solo Findings: 0

Title

Unused variable after declaration (Version)

Vulnerability details *

Impact

Detailed description of the impact of this finding.

Thereโ€™s no function to change or modify the string variable; version. This data type is stored on slot zero of the contract. This also combines to the byte code of the contract.

Proof of Concept

Provide direct links to all referenced code in GitHub. Add screenshots, logs, or any other relevant proof that illustrates the concept. https://github.com/FraxFinance/fraxlend/blob/0f9bc5ddd6872fba04f4d8fb67c92a88416d19b2/src/contracts/FraxlendPairCore.sol#L51

If variable is needed in contract, it could be made immutable or constant to prevent occupying storage. This also can still be viewed with the public visibility.

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax ยฉ 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter