20,000 USDC
View results
Submission Details
Severity: high
Valid

No slippage protection when selling profits

Summary

When profits are swapped for WETH in Fees.sol, no slippage protection is applied whatsoever when executing the swap.

Vulnerability Details

In Fees.sol#L38, the swap is executed with amountOutMinimum: 0 which opens the door for a front-running attack.

Impact

Protocol can incur a loss when selling tokens with no slippage protection.

Tools Used

Manual review

Recommendations

Pass amountOutMin as an argument to sellProfits().

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.