PoolTogether micro contest #1 - jonah1005's results

A protocol for no loss prize savings on Ethereum

General Information

Platform: Code4rena

Start Date: 29/07/2021

Pot Size: $20,000 USDC

Total HM: 8

Participants: 12

Period: 3 days

Judge: LSDan

Total Solo HM: 2

Id: 24

League: ETH

PoolTogether

Findings Distribution

Researcher Performance

Rank: 9/12

Findings: 2

Award: $565.86

🌟 Selected for report: 0

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: cmichel

Also found by: hickuphh3, jonah1005, pauliax

Labels

bug
duplicate
2 (Med Risk)
SwappableYieldSource

Awards

565.8571 USDC - $565.86

External Links

Handle

jonah1005

Vulnerability details

Impact

In function redeemToken, it uses transferFrom instead of transfer. It might stop users from redeeming tokens.

Proof of Concept

https://github.com/pooltogether/swappable-yield-source/blob/89cf66a3e3f8df24a082e1cd0a0e80d08953049c/contracts/SwappableYieldSource.sol#L240

Tools Used

None

Use safeTransfer instead.

#0 - PierrickGT

2021-08-06T16:16:39Z

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter