20,000 USDC
View results
Submission Details
Severity: medium
Valid

Fees.sellProfits doesn't have deadline protection

Summary

Fees.sellProfits doesn't have deadline protection.

Vulnerability Details

deadline protection is needed in order to not allow anyone to cache your tx in the pool and then execute it, when uniswap prices has changed. This can protect users from losses.
Currently Fees.sellProfits contract provides block.timestamp as deadline, which means that tx can be executed any time.

Impact

Loss of funds for seller.

Tools Used

VsCode

Recommendations

Make ability for seller to provide deadline.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.