Kuiper contest - shenwilly's results

Automated portfolio protocol.

General Information

Platform: Code4rena

Start Date: 16/09/2021

Pot Size: $50,000 USDC

Total HM: 26

Participants: 30

Period: 7 days

Judge: GalloDaSballo

Total Solo HM: 17

Id: 36

League: ETH

Kuiper

Findings Distribution

Researcher Performance

Rank: 24/30

Findings: 3

Award: $279.33

🌟 Selected for report: 2

πŸš€ Solo Findings: 0

Findings Information

🌟 Selected for report: hack3r-0m

Also found by: JMukesh, itsmeSTYJ, leastwood, shenwilly

Labels

bug
duplicate
2 (Med Risk)
sponsor confirmed

Awards

131.4735 USDC - $131.47

External Links

Handle

shenwilly

Vulnerability details

Impact

It's best practice to use OpenZeppelin’s safeTransfer & safeTransferFrom for token transfers. While most of the code already uses them, withdrawBounty from Auction.sol is missing it, which could cause silent failure of transfers.

Proof of Concept

https://github.com/code-423n4/2021-09-defiProtocol/blob/52b74824c42acbcd64248f68c40128fe3a82caf6/contracts/contracts/Auction.sol#L146

Change transfer to safeTransfer.

#1 - GalloDaSballo

2021-11-30T23:36:52Z

Duplicate of #196

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax Β© 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter