Lack of slippage protection
sellProfits() forces users to swap their _profits tokens to WETH, but doesn't allow them to specify any slippage values. Tokens are swapped and always use 0 for min out meaning that deposits will be sandwiched and stolen.
All swap token can be sandwiched and stolen
vscode
Allow user to specify slippage parameters.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.