Vader Protocol contest - pauliax's results

Liquidity Protocol anchored by Native Stablecoin with Slip-Based Fees AMM, IL protection and Synthetics.

General Information

Platform: Code4rena

Start Date: 21/12/2021

Pot Size: $30,000 USDC

Total HM: 20

Participants: 20

Period: 5 days

Judge: Jack the Pug

Total Solo HM: 13

Id: 70

League: ETH

Vader Protocol

Findings Distribution

Researcher Performance

Rank: 10/20

Findings: 3

Award: $390.23

🌟 Selected for report: 3

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: TomFrenchBlockchain

Also found by: pauliax, robee

Labels

bug
duplicate
2 (Med Risk)
sponsor confirmed
USDV

Awards

116.4719 USDC - $116.47

External Links

Handle

pauliax

Vulnerability details

Impact

functions mint and burn of USDV should allow the user to specify min amounts to receive. This would help the user to avoid a huge slippage. Another reason is that price is fetched from lbt but this address can be changed anytime (function setLBTwap), so in theory users can be frontrunned and a malicious lbt injected.

To enhance the protection of users, I suggest adding slippage tolerance parameters to the aforementioned functions.

#0 - jack-the-pug

2022-03-13T06:31:44Z

Dup #2

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter