Revert Lend - maxim371's results

A lending protocol specifically designed for liquidity providers on Uniswap v3.

General Information

Platform: Code4rena

Start Date: 04/03/2024

Pot Size: $88,500 USDC

Total HM: 31

Participants: 105

Period: 11 days

Judge: ronnyx2017

Total Solo HM: 7

Id: 342

League: ETH

Revert

Findings Distribution

Researcher Performance

Rank: 99/105

Findings: 1

Award: $6.61

🌟 Selected for report: 0

🚀 Solo Findings: 0

Awards

6.6125 USDC - $6.61

Labels

bug
2 (Med Risk)
downgraded by judge
insufficient quality report
partial-50
:robot:_03_group
duplicate-175

External Links

Lines of code

https://github.com/code-423n4/2024-03-revert-lend/blob/435b054f9ad2404173f36f0f74a5096c894b12b7/src/V3Oracle.sol#L363

Vulnerability details

Impact

pool.slot0` can be easily manipulated via flash loans to sandwich attack users. The sqrtPriceX96 is pulled from Uniswap.slot0, which is the most recent data point and can be manipulated easily via MEV bots and Flashloans with sandwich attacks; which can cause the loss of funds when interacting with the Uniswap.swap function.

Proof of Concept

https://github.com/code-423n4/2024-03-revert-lend/blob/435b054f9ad2404173f36f0f74a5096c894b12b7/src/V3Oracle.sol#L363

https://github.com/code-423n4/2024-03-revert-lend/blob/435b054f9ad2404173f36f0f74a5096c894b12b7/src/V3Oracle.sol#L357-L374

Tools Used

Manual Review

Use UniswapV3 TWAP or Chainlink Price Oracle.

Assessed type

Uniswap

#0 - c4-pre-sort

2024-03-19T10:03:00Z

0xEVom marked the issue as duplicate of #191

#1 - c4-pre-sort

2024-03-19T10:03:06Z

0xEVom marked the issue as sufficient quality report

#2 - c4-pre-sort

2024-03-19T10:03:09Z

0xEVom marked the issue as insufficient quality report

#3 - c4-judge

2024-03-31T14:28:11Z

jhsagd76 marked the issue as duplicate of #175

#4 - c4-judge

2024-03-31T14:43:41Z

jhsagd76 marked the issue as partial-50

#5 - c4-judge

2024-04-01T15:43:40Z

jhsagd76 changed the severity to 2 (Med Risk)

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter