veRWA - merlin's results

Incentivization Primitive for Real World Assets on Canto

General Information

Platform: Code4rena

Start Date: 07/08/2023

Pot Size: $36,500 USDC

Total HM: 11

Participants: 125

Period: 3 days

Judge: alcueca

Total Solo HM: 4

Id: 274

League: ETH

Canto

Findings Distribution

Researcher Performance

Rank: 62/125

Findings: 1

Award: $9.82

QA:
grade-a

🌟 Selected for report: 0

🚀 Solo Findings: 0

Low

Setting high CANTO rewards per epoch from malicious voters in governance

CANTO's governance participants can call the LendingLedger.setRewards function with very high CANTO rewards per epoch, which could lead to the distribution of an enormous amount of rewards. If LendingLedger.setRewards was called with incorrect rewards for a specific epoch, the changes cannot be reversed.

#0 - c4-judge

2023-08-22T13:55:19Z

alcueca marked the issue as grade-a

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter