Missing slippage exposes swap operations to MEV
When swap Beans for the non-bean token of the SOP well, it provides the amountOutMin to be zero. which exposes the swap to unlimited MEV.
https://github.com/Cyfrin/2024-02-Beanstalk-1/blob/main/protocol/contracts/beanstalk/sun/SeasonFacet/Weather.sol#L207
Users can lose all amount swapped to MEV
Manual Review
Allow users to pass acceptable amountOut instead of zero
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.