The Standard

The Standard
DeFiHardhat
20,000 USDC
View results
Submission Details
Severity: low
Invalid

LiquidationPoolManager ERC20 allowances

Summary

LiquidationPoolManager approves LiquidationPool to spend EUROs and other ERC20 tokens for fee and reward distribution (line 39 and 78). Depending on the stakes in the pool, these allowances might not be used up in the distribution logic. While the remaining tokens are immediately forwarded to a protocol controlled address, it would be best to reset these allowances to 0.

Impact

No attack vector has been identified specifically for this issue. However, in combination with the High Risk vulnerability submitted for LiquidationPool, this could potentially allow draining tokens from LiquidationPoolManager.

Recommendations

Reset allowances after fee and reward distribution.

Updates

Lead Judging Commences

hrishibhat Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Out of scope
Assigned finding tags:

pool-approval

informational/invalid

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.