Dopex - ginlee's results

A rebate system for option writers in the Dopex Protocol.

General Information

Platform: Code4rena

Start Date: 21/08/2023

Pot Size: $125,000 USDC

Total HM: 26

Participants: 189

Period: 16 days

Judge: GalloDaSballo

Total Solo HM: 3

Id: 278

League: ETH

Dopex

Findings Distribution

Researcher Performance

Rank: 114/189

Findings: 1

Award: $45.32

🌟 Selected for report: 0

🚀 Solo Findings: 0

Findings Information

Labels

bug
2 (Med Risk)
partial-50
sufficient quality report
duplicate-1032

Awards

45.3151 USDC - $45.32

External Links

Lines of code

https://github.com/code-423n4/2023-08-dopex/blob/eb4d4a201b3a75dd4bddc74a34e9c42c71d0d12f/contracts/reLP/ReLPContract.sol#L291-L292

Vulnerability details

Impact

DeFi platforms must allow users to specify a slippage parameter: the minimum amount of tokens they want to provide during adding liquidity

Proof of Concept

https://github.com/code-423n4/2023-08-dopex/blob/eb4d4a201b3a75dd4bddc74a34e9c42c71d0d12f/contracts/reLP/ReLPContract.sol#L291-L292 0 is provided as slippage params which may lead to user loss of fund

Tools Used

Manual Review

Platforms should also provide a sensible default if the user doesn't specify a value, but user-specified slippage parameters must always override platform defaults.

Assessed type

Other

#0 - c4-pre-sort

2023-09-10T10:49:29Z

bytes032 marked the issue as low quality report

#1 - c4-pre-sort

2023-09-10T10:50:14Z

bytes032 marked the issue as duplicate of #1259

#2 - c4-pre-sort

2023-09-11T07:52:13Z

bytes032 marked the issue as sufficient quality report

#3 - c4-pre-sort

2023-09-11T07:53:15Z

bytes032 marked the issue as duplicate of #1032

#4 - c4-judge

2023-10-15T19:20:19Z

GalloDaSballo marked the issue as partial-50

#5 - GalloDaSballo

2023-10-15T19:21:09Z

Recommendation is wrong + content is off

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter