Venus Protocol Isolated Pools - lanrebayode77's results

Earn, Borrow & Lend on the #1 Decentralized Money Market on the BNB Chain

General Information

Platform: Code4rena

Start Date: 08/05/2023

Pot Size: $90,500 USDC

Total HM: 17

Participants: 102

Period: 7 days

Judge: 0xean

Total Solo HM: 4

Id: 236

League: ETH

Venus Protocol

Findings Distribution

Researcher Performance

Rank: 9/102

Findings: 1

Award: $1,807.40

🌟 Selected for report: 0

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: SaeedAlipoor01988

Also found by: lanrebayode77

Labels

bug
2 (Med Risk)
satisfactory
duplicate-122

Awards

1807.3974 USDC - $1,807.40

External Links

Lines of code

https://github.com/code-423n4/2023-05-venus/blob/8be784ed9752b80e6f1b8b781e2e6251748d0d7e/contracts/WhitePaperInterestRateModel.sol#L96

Vulnerability details

Impact

The Utilization Rate could throw a value in a case where borrows is greater than zero if reserves is greater than both cash and borrows. This will inturn lead to getting both supply rate and borrow rate calculations wrong.

A revert should be made in such scenario where reserves is greater than cash and borrows or a different utilization formula for such cases.

Assessed type

Math

#0 - c4-judge

2023-05-18T02:06:13Z

0xean marked the issue as duplicate of #122

#1 - c4-judge

2023-06-05T14:12:22Z

0xean marked the issue as satisfactory

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter