20,000 USDC
View results
Submission Details
Severity: medium
Valid

Fees.sellProfits() swap with deadline: block.timestamp offers no protection

Summary

Fees.sellProfits() swap with deadline: block.timestamp offers no protection.

Vulnerability Details

Whichever block the txn will be included in will be block.timestamp, so setting the deadline to block.timestamp offers no protection as validators can hold the transaction indefinitely.

Impact

The transaction can be held indefinitely for MEV until it results in maximum slippage.

Tools Used

Manual

Recommendations

Allow function caller to specify deadline parameter.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.