The Standard

The Standard
DeFiHardhat
20,000 USDC
View results
Submission Details
Severity: medium
Invalid

`LiquidationPool.so`::`distributeAssets`PAXG uses fee on transfer and an attacker can drain tokens from the pool using flashloan

Summary

Due to the fees on transfer for PAXG, liquidity providers will receive less than expected on the asset distribution in LiquidationPool.so::distributeAssets.
Also PAXG uses fee on transfer and an attacker can drain tokens from the pool using flashloan similar to what happened with STA.

Vulnerability Details

Due to the fees on transfer for PAXG, liquidity providers will receive less than expected on the asset distribution in LiquidationPool.so::distributeAssets.
Also PAXG uses fee on transfer and an attacker can drain tokens from the pool using flashloan similar to what happened with STA.

Impact

Liquidity providers receive less because of the fees on transfer on PAXG.

Tools Used

Manual Review

Recommendations

Remove PAXG and add another safer token. You will court the attention of attackers just by using PAXG. Drop it for another safer token.

Updates

Lead Judging Commences

hrishibhat Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

fee-on-transfer

hrishibhat Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Out of scope
Assigned finding tags:

fee-on-transfer

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.