Canto Dex Oracle contest - peritoflores's results

Execution layer for original work.

General Information

Platform: Code4rena

Start Date: 07/09/2022

Pot Size: $20,000 CANTO

Total HM: 7

Participants: 65

Period: 1 day

Judge: 0xean

Total Solo HM: 3

Id: 159

League: ETH

Canto

Findings Distribution

Researcher Performance

Rank: 31/65

Findings: 1

Award: $39.22

🌟 Selected for report: 0

🚀 Solo Findings: 0

Lines of code

https://github.com/code-423n4/2022-09-canto/blob/65fbb8b9de22cf8f8f3d742b38b4be41ee35c468/src/Swap/BaseV1-core.sol#L93-L94

Vulnerability details

PoC

There are some tokens with more than 18 decimals. For example (YAMv2 has 24 decimals).

However, all you math is based on the fact that the maximum number of digits for a token is 18.

Check that the tokens has 18 digits or less when creating the pair.

#0 - nivasan1

2022-09-10T19:59:00Z

duplicate #25

#1 - 0xean

2022-09-12T14:44:42Z

downgraded to QA per #25 - warden has no QA report, so this will stand alone

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter