A MEV bot can steal from swap and return none WETH tokens to Fees contract.
The amountOutMinimum parameter in ExactInputSingleParams is necessary to calculate the expected amount of WETH tokens that the Fees contract will receive. By setting it to zero, any MEV bot can extract value from this transaction, leading to loss of rewards for users.
Loss of users rewards to MEV bot.
Manual Review
It is recommended to add a variable to use as amountOutMinimum or calculate it.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.