stake.link

stake.link
DeFiHardhatBridge
27,500 USDC
View results
Submission Details
Severity: medium
Invalid

removeWhitelistedChain function does not check pending txn

Summary

removeWhitelistedChain does not check for any pending transaction that may lead to failure of transaction.

Vulnerability Details

removeWhitelistedChain does not have any type of check to identify any pending transaction on a given chain which may lead to failure of transaction which is in process and will be stuck if chain is removed during that time.

Impact

Removing chain will stuck any pending transaction and loss of funds for user if chain is removed during sending of tokens as there is no check in function for removeWhitelistedChain to lookout for such unprocessed transactions.

Tools Used

Manual Analysis.

Recommendations

The recommendation is made to have check for any unprocessed/pending transaction that might stuck during removal of chain from the function of removeWhitelistedChain in the contract SDLPoolCCIPControllerPrimary.

Updates

Lead Judging Commences

0kage Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
saaj Submitter
almost 2 years ago
0kage Lead Judge
almost 2 years ago
0kage Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.