40,000 USDC
View results
Submission Details
Severity: high

No slippage control

Summary

No slippage control in confirmReceipt function

Vulnerability Details

The auditer(seller) wants 10 000$ in ethers(let's say that 1 ether = 2000$), so the Buyer will make a newEscrow that will have price 5 and tokenContract will be the ether address. But when the Buyer confirmReceipt, ether can have a drop and the Auditor will not get his money

Impact

Loss of funds of the Auditor

Tools Used

Manual Review

Recommendations

use slippage control

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.