40,000 USDC
View results
Submission Details
Severity: low
Valid

missed check for the arbiter address

Vulnerability Details

the protocol should make sure that the arbiter is not the buyer or the seller as this may lead to loss of funds of the seller or the buyer

Impact

if the buyer set himself as the arbiter it will lead to the seller not receiving his money

Tools Used

manual review

Recommendations

add the check :

if (i_arbiter == i_buyer || i_arbiter == i_seller ) {revert();}

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.