Steadefi

Steadefi
DeFiHardhatFoundryOracle
35,000 USDC
View results
Submission Details
Severity: low
Invalid

Token Withdrawals Circumvent Approval Checks

Summary

The contract functions do not validate that sufficient token approval has been granted prior to transferring balances. This allows an attacker to move tokens without the owner's consent.

Impact

Tokens can be stolen by bypassing approval

Tools Used

Manual Review

Recommendations

Validate the contract has been approved to move at least the transfer amount before transferring any tokens. Revert on insufficient approval.

Updates

Lead Judging Commences

hans Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.