The withdraw function lacks any time restriction
The withdraw function lacks any time restriction, allowing users to front-run the reward update when they detect an increase in WETH rewards in the pool. This enables them to quickly deposit funds and call the withdraw function to withdraw the increased rewards.
Unfair Advantage in WETH Reward Claims
Vscode
To address this issue, proper access controls and/or time restrictions should be implemented in the withdraw function.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.