DittoETH

Ditto
DeFiFoundryOracle
55,000 USDC
View results
Submission Details
Severity: high
Invalid

User is adding `Unit price in eth for erc sold` which could be dangerous

Summary

User is adding Unit price in eth for erc sold which could be dangerous. Assuming that the user will input correct amount of ETH is very dangerous.

Vulnerability Details

The vulnerability lies in the function createLimitShort() where user-provided values for price is used without sufficient validation or reliance on decentralized oracles for accurate pricing information. Leaving this argument in user hand is very dangerous as user can input any price that favors him

Impact

If exploited, this vulnerability could result in incorrect market behavior, leading to financial losses for users of the contract. In the worst case, it may even expose the system to malicious attacks.

Tools Used

Manual Review

Recommendations

It is recommended to get the price of asset from chainlink

Updates

Lead Judging Commences

0xnevi Lead Judge
almost 2 years ago
0xnevi Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.