Yieldy contest - aga7hokakological's results

A protocol for gaining single side yields on various tokens.

General Information

Platform: Code4rena

Start Date: 21/06/2022

Pot Size: $50,000 USDC

Total HM: 31

Participants: 99

Period: 5 days

Judges: moose-code, JasoonS, denhampreen

Total Solo HM: 17

Id: 139

League: ETH

Yieldy

Findings Distribution

Researcher Performance

Rank: 59/99

Findings: 2

Award: $79.73

🌟 Selected for report: 0

🚀 Solo Findings: 0

Access control missing for initialize() function

It is quite possible that while initializing contract it can be front-run and can be set by some malicious user which can cause trouble and loss of funds.

POC:

function initialize( address _stakingToken, address _yieldyToken, address _tokeToken, address _tokePool, address _tokeManager, address _tokeReward, address _liquidityReserve, address _feeAddress, address _curvePool, uint256 _epochDuration, uint256 _firstEpochEndTime ) external initializer { }

tools used:

manual analysis

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter