Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Valid

Improper init value for claim in staking

Summary

Improper init value for claim in staking

Vulnerability Details

  • Alice mint soulmate token in timestamp A.

  • Alice deposit soulmate token in staking in timestamp B.

  • When Alice tries to claim rewards, it's better to calculate rewards from timestampB not timestampA.

Impact

Users can claim more rewards than expected.

Tools Used

Manual

Recommendations

Record timestamp when user deposit/withdraw, and update rewards timely.

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

finding-claimRewards-multi-deposits-time

High severity, this allows users to claim additional rewards without committing to intended weekly staking period via multi-deposit/deposit right before claiming rewards.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.