TempleGold

TempleDAO
Foundry
25,000 USDC
View results
Submission Details
Severity: low
Valid

No way to recover tokens when auction has ended without any bids in DaiGoldAuction

Summary

The DaiGoldAuction expects that there should be atleast 1 participant in order to perform claims of the gold token, but if in case no bids have happened then the amount allocated for that particular auction epoch will be stuck and can't be recovered.

The chances of this happening are kind of low, but the impact is high, therefore it should be a medium.

Vulnerability Details

When an auction is started, the epoch info is updated with the gold amount allocated and it is expected that for the users to have bid in the contract in order to perform claim.

But if no users participated in the bid process, then there is no one who can have a claim and it is expected but there arises a vulnerability issue which involves lock of those funds allocated for this auction epoch, as there is now no way to reuse those stuck tokens or recover them.

Impact

No way to recover funds for the auction for which no bid occurred.

Tools Used

No specific tools used

Recommendations

Add a mechanism to recover the tokens to a safe address or again allocated those funds for the next auction.

Updates

Lead Judging Commences

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Auctioned tokens cannot be recovered for epochs with empty bids in DaiGoldAuction

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.