TempleGold

TempleDAO
Foundry
25,000 USDC
View results
Submission Details
Severity: medium
Invalid

Users can game zero-bid auctions

Summary

Users can game zero-bid auctions.

Vulnerability Details

If no users participate in an auction because it was too short, the system is new, or any other reason, a single user can claim the entire proceeds with just 1 wei of our bid token. This undermines the purpose of the auction, which is in a way to "swap" auction tokens for bid tokens.

Impact

In rare cases, users can claim the full totalAuctionTokenAmount with a minor bid.

Tools Used

Manual review

Recommendations

Implement a minimum bid limit to prevent, or at least reduce the impact of such occurrences. Even better if the auction has a total min bid, where it gets canceled if that amount is not reached (but for that new functions and mechanics would need to be introduced).

Updates

Lead Judging Commences

inallhonesty Lead Judge
11 months ago
inallhonesty Lead Judge 11 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.