JPEG'd contest - pauliax's results

Bridging the gap between DeFi and NFTs.

General Information

Platform: Code4rena

Start Date: 07/04/2022

Pot Size: $100,000 USDC

Total HM: 20

Participants: 62

Period: 7 days

Judge: LSDan

Total Solo HM: 11

Id: 107

League: ETH

JPEG'd

Findings Distribution

Researcher Performance

Rank: 45/62

Findings: 1

Award: $151.51

🌟 Selected for report: 0

🚀 Solo Findings: 0

Awards

151.5077 USDC - $151.51

Labels

bug
QA (Quality Assurance)
sponsor acknowledged

External Links

  • In LPFarming if the owner invokes setContractWhitelisted to false for a previously whitelisted contract, this user will not be able to withdraw or claim the rewards. I don't know if this is intentional or not, but an alternative solution would be to have an actions enum and mapping to the boolean field to make it more manageable.

  • STRATEGIST_ROLE has a lot of privileges that increase the risk of a rug-pull. A strategist can first invoke setVault, then invoke setStrategy or withdrawAll to transfer the tokens to the vault, or inCaseTokensGetStuck to drain any tokens from the strategies that were deposited by the users. In case one of the strategists' accounts is compromised, they can run away with all the tokens.

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter