The owner can manipulate shares and execute a rug pull by setting feePerSecond
excessively high.
the owner have the ability to set the FeePerSecond
which is uint256
to any . (it's not bounded), by calling the function updateFeePerSecond() the the owner can raise the fee
too high which will mint LP
the Treasury contract which also the owner have the ability to change it's address to any.
With the increased LP token supply, the value of users' shares is diluted, rendering them nearly worthless.
the owner then can withdraw this lps and rugpull the users.
users lose thier deposits .
manual review .
set a max
and min
fee that the owner can set perSecond.
Impact: High Likelihood: Low Centralization risk is regarded a known issue. This tag will include all submissions : - Admin setter functions without validations
Impact: High Likelihood: Low Centralization risk is regarded a known issue. This tag will include all submissions : - Admin setter functions without validations
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.