Steadefi

Steadefi
DeFiHardhatFoundryOracle
35,000 USDC
View results
Submission Details
Severity: medium
Invalid

REFUND_TO_ZERO_ADDRESS_POSSIBILITY

Summary

Vulnerability Details

In GMXVault ETH sent by GMX is refunded to _store.refundee. However it's not set in _store initialisation in GMXVault and _store.refundee is a zero address. Value of _store.refundee is set in GMXCompound.compound, GMXEmergency.emergencyPause and others however they can not be called and funds will be sent to the zero address

Impact

GMX refund lost

Tools Used

Recommendations

Initialise refundee with the store initialisation, add fallback refundee if _store.refundee is not set

Updates

Lead Judging Commences

hans Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.