DittoETH

Ditto
DeFiFoundryOracle
55,000 USDC
View results
Submission Details
Severity: medium
Invalid

BridgeRouterFacet.withdrawTapp should update yield

Summary

BridgeRouterFacet.withdrawTapp should update yield.

Vulnerability Details

BridgeRouterFacet.withdrawTapp allows dao to withdraw fees from the protocol. This function will change s.vaultUser[vault][address(this)].ethEscrowed.

Shorters in the protocol receive rewards for the amount of zeth collateral that they have provided. Protocol also receives part of this funds as fee. As result this funds also earn additional fee. But in case if fees are withdrawn before updateYield call, then protocol will not receive additional yields.

Impact

Protocol receives less amount of yields.

Tools Used

VsCode

Recommendations

When withdraw fees, make sure that updateYield is called.

Updates

Lead Judging Commences

0xnevi Lead Judge
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.