Lybra Finance - halden's results

A protocol building the first interest-bearing omnichain stablecoin backed by LSD.

General Information

Platform: Code4rena

Start Date: 23/06/2023

Pot Size: $60,500 USDC

Total HM: 31

Participants: 132

Period: 10 days

Judge: 0xean

Total Solo HM: 10

Id: 254

League: ETH

Lybra Finance

Findings Distribution

Researcher Performance

Rank: 89/132

Findings: 1

Award: $57.90

QA:
grade-a

🌟 Selected for report: 0

🚀 Solo Findings: 0

Awards

57.9031 USDC - $57.90

Labels

bug
grade-a
QA (Quality Assurance)
sponsor acknowledged
Q-05

External Links

[L-01] Do not use hard-coded address

Instances: EUSDMiningIncentives, LybraRETHVault

[L-02] Do not set duration to zero

If new duration is eqaul to 0 than will occur zero division error in notifyRewardAmount function stakerewardV2pool

[L-03] Use modifier when is possible

Instance: LybraRETHVault

[L-04] Not handled result from function

The return value from function EUSD.transferShares is not handled properly. Instance: 120, 131

[L-05] Zero convert to PeUSD is possible

If eusdAmount is equal to zero than zero converting to PeUSD is possible in convertToPeUSD function. Instance: PeUSDMainnetStableVision

[L-06] Wrong event argument

Wrong event argument is used in emitting of Flashloaned event. It should be shareAmount instead of eusdAmount Instance: PeUSDMainnetStableVision

[L-06] Fee upper limit is missed

Fee upper limit is missed when new value for fee is setted. Fee for flashloan can be updated to 10_000 and to get all shares of user. Instance: PeUSDMainnetStableVision

[L-07] Wrong commented address

Anothor address is used for WBETH. Instance: LybraWbETHVault

[L-08] Missed check for zero amount

Regarding comment above function burn the given amount from user should be bigger than zero. LybraEUSDVaultBase

[L-09] Possible array length mismatch

It is possible length mismatch in setTokenMiner function for arrays _contracts and _bools. LybraConfigurator

#0 - c4-sponsor

2023-07-27T07:06:21Z

LybraFinance marked the issue as sponsor acknowledged

#1 - c4-judge

2023-07-28T00:05:03Z

0xean marked the issue as grade-a

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter