Notional contest - sirhashalot's results

Fixed rates, now in crypto.

General Information

Platform: Code4rena

Start Date: 27/01/2022

Pot Size: $75,000 USDC

Total HM: 10

Participants: 26

Period: 7 days

Judge: pauliax

Total Solo HM: 5

Id: 81

League: ETH

Notional

Findings Distribution

Researcher Performance

Rank: 16/26

Findings: 3

Award: $426.35

🌟 Selected for report: 2

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: cmichel

Also found by: 0x1f8b, TomFrenchBlockchain, UncleGrandpa925, WatchPug, defsec, leastwood, pauliax, sirhashalot

Labels

bug
duplicate
2 (Med Risk)

Awards

171.7186 USDC - $171.72

External Links

Handle

sirhashalot

Vulnerability details

Impact

Chainlink's documentation listed the latestAnswer() function as deprecated. This function doesn't revert if no answer is available but returns 0, and the return value of latestanswer() is not checked in the Notional code. In fact, Chainlink removed their deprecated function documentation from their website but Internet Archive shows latestAnswer() was deprecated even in March 2021. Several past code4rena findings identify this finding as medium risk.

Proof of Concept

Line 176 of EIP1271Wallet.sol calls the deprecated Chainlink latestAnswer() function

Use Chainlink V3 API functions: https://docs.chain.link/docs/price-feeds-api-reference/

#0 - jeffywu

2022-02-06T15:10:31Z

Duplicate #178

#1 - pauliax

2022-02-12T12:14:23Z

A duplicate of #197

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter