20,000 USDC
View results
Submission Details
Severity: high
Valid

No slippage protection in sellProfits() function?

Summary

No slippage protection in sellProfits() function?

This caught my attention, while wrapping up my audit of this contest, regarding parameter of ISwapRouter.ExactInputSingleParams({:

amountOutMinimum: 0,

Vulnerability Details

From my limited understanding this is related to slippage, and if zero, there is no slippage protection...
Vulnerable to sandwich attacks?

Impact

Can swap and get out a lot less than expected...?

Tools Used

VSC, manual, overtiredness...

Recommendations

Add a suitable non-zero amountOutMinimum amount...

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.