sellProfits allows users to swap tokens but lacks the capability to specify any slippage values.
The sellProfits function uses Uniswap to swap tokens with amountOutMinimum = 0
, leaving users vulnerable to sandwich attacks and potential loss of all their tokens.
User can be sandwiched, leading to the potential loss of all tokens.
Manual review
To mitigate the risks, allow users to specify a slippage parameter.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.