Salty.IO - developerjordy's results

An Ethereum-based DEX with zero swap fees, yield-generating Automatic Arbitrage, and a native WBTC/WETH backed stablecoin.

General Information

Platform: Code4rena

Start Date: 16/01/2024

Pot Size: $80,000 USDC

Total HM: 37

Participants: 178

Period: 14 days

Judge: Picodes

Total Solo HM: 4

Id: 320

League: ETH

Salty.IO

Findings Distribution

Researcher Performance

Rank: 173/178

Findings: 1

Award: $0.78

🌟 Selected for report: 0

🚀 Solo Findings: 0

Lines of code

https://github.com/code-423n4/2024-01-salty/blob/main/src/stable/CollateralAndLiquidity.sol#L154 https://github.com/code-423n4/2024-01-salty/blob/main/src/staking/StakingRewards.sol#L107

Vulnerability details

the cooldown restriction prevents users from being liquidated, this can only be done until the cooldown period has passed.

Impact

This restriction may prevent timely liquidation of users.

Tools used

Manual review

Liquidating users shouldn't depend on the cooldown period.

Change line 154 in the liquidateUser method

- _decreaseUserShare( wallet, collateralPoolID, userCollateralAmount, true ); 
+ _decreaseUserShare( wallet, collateralPoolID, userCollateralAmount, false ); 

Assessed type

Timing

#0 - c4-judge

2024-01-31T22:47:55Z

Picodes marked the issue as duplicate of #891

#1 - c4-judge

2024-01-31T22:48:00Z

Picodes marked the issue as duplicate of #891

#2 - c4-judge

2024-01-31T22:48:06Z

Picodes changed the severity to 3 (High Risk)

#3 - c4-judge

2024-02-21T16:52:29Z

Picodes marked the issue as satisfactory

#4 - thebrittfactor

2024-02-21T21:53:39Z

For transparency, the judge confirmed issue should be marked as duplicate-312.

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter