Beginner FriendlyFoundryDeFiOracle
100 EXP
View results
Submission Details
Severity: high
Invalid

There is no provision in the deposit function to update the balance after a deposit is made

Summary

After making deposits, there was no provision in the deposit function to keep track of the amount deposited.

Vulnerability Details

The reason why not keeping track of how much has been deposited is an issue is that a possible reentrant can be called through the redeem function making the attacker exploit the contract for the funds of other users.

Impact

Tools Used

Manual Review

Recommendations

Update the s_tokenToAssetToken in deposit function and ensure that CEI is implemented to avoid any reentrancy.

Updates

Lead Judging Commences

0xnevi Lead Judge
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Vague generalities

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.