Tally contest - cmichel's results

The community owned and operated Web3 wallet.

General Information

Platform: Code4rena

Start Date: 20/10/2021

Pot Size: $30,000 ETH

Total HM: 5

Participants: 15

Period: 3 days

Judge: 0xean

Total Solo HM: 3

Id: 44

League: ETH

Tally

Findings Distribution

Researcher Performance

Rank: 4/15

Findings: 3

Award: $1,288.31

🌟 Selected for report: 4

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: elprofesor

Also found by: JMukesh, Koustre, WatchPug, cmichel, pauliax

Labels

bug
duplicate
2 (Med Risk)

Awards

240.9613 USDC - $240.96

External Links

Handle

cmichel

Vulnerability details

The address.transfer function is used in sweepFees and (and swapByQuote) to send ETH to an account. It is restricted to a low amount of GAS and might fail if GAS costs change in the future or if feeRecipient is a smart contract and its fallback function handler implements anything non-trivial.

Consider using the lower-level .call{value: value} instead and check it's success return value.

#0 - Shadowfiend

2021-11-04T16:22:12Z

Duplicate of #20.

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter