20,000 USDC
View results
Submission Details
Severity: high
Valid

Fees.sellProfits()::Lack of slippage protection

Summary

Lack of slippage protection

Vulnerability Details

sellProfits() forces users to swap their _profits tokens to WETH, but doesn't allow them to specify any slippage values. Tokens are swapped and always use 0 for min out meaning that deposits will be sandwiched and stolen.

Impact

All swap token can be sandwiched and stolen

Tools Used

vscode

Recommendations

Allow user to specify slippage parameters.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.