Overlay Protocol contest - gzeon's results

A protocol for trading #DeFi data streams.

General Information

Platform: Code4rena

Start Date: 16/11/2021

Pot Size: $50,000 ETH

Total HM: 11

Participants: 17

Period: 7 days

Judge: LSDan

Total Solo HM: 8

Id: 49

League: ETH

Overlay Protocol

Findings Distribution

Researcher Performance

Rank: 15/17

Findings: 2

Award: $273.10

🌟 Selected for report: 0

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: defsec

Also found by: WatchPug, cmichel, gzeon, nathaniel, pauliax

Labels

bug
duplicate
2 (Med Risk)

Awards

0.0489 ETH - $226.14

External Links

Handle

gzeon

Vulnerability details

Impact

There is no check when setting marginRewardRate, if it is set to any value > FixedPoint.ONE (i.e. 1e18) it would lead to underflow at L403

Proof of Concept

https://github.com/code-423n4/2021-11-overlay/blob/1833b792caf3eb8756b1ba5f50f9c2ce085e54d0/contracts/collateral/OverlayV1OVLCollateral.sol#L102

Add related check in setMarketInfo

#0 - mikeyrf

2021-12-06T23:30:33Z

duplicate #77 - bounds on governance params

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter