20,000 USDC
View results
Submission Details
Severity: high
Valid

sellProfits will lose users fund with 0 slippage

Summary

When sell profits, user will lose fund because protocol has no slippage protection.

Vulnerability Details

When user sell profits for ETH, protocol call uniswap v3 router exactInputSingle function to sell profits for ETH, but there is no slippage protection because amountOutMinimum is set to 0.

Impact

All profits tokens can be sandwiched and stolen by malicious MEV.

Tools Used

vscode, Manual Review

Recommendations

Allow users to specify slippage parameters for all profits tokens.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!