20,000 USDC
View results
Submission Details
Severity: medium
Valid

Unfair Advantage in WETH Reward Claims

Summary

The withdraw function lacks any time restriction

Vulnerability Details

The withdraw function lacks any time restriction, allowing users to front-run the reward update when they detect an increase in WETH rewards in the pool. This enables them to quickly deposit funds and call the withdraw function to withdraw the increased rewards.

Impact

Unfair Advantage in WETH Reward Claims

Tools Used

Vscode

Recommendations

To address this issue, proper access controls and/or time restrictions should be implemented in the withdraw function.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.