TempleGold

TempleDAO
Foundry
25,000 USDC
View results
Submission Details
Severity: low
Invalid

Race-conditioning on bidding on the last second to win the Auction

Vulnerability Details

There is no mechanism that extends the auction duration whenever the Bid was, So if a user bidded on the last second he can secure the auction without other participants nor the Prev Highest bidder noticed.

As we can see in SpiceAuction::bid(), it just added the amount. So Race Condition can occur by users bidding on the last second to secure winning the auction.

Impact

Unfar auction process to users.

Tools Used

Manual Review

Recommendations

Add an extensionTime feature, where if the Bid just before auction ends (this can be 1 Hour for example), you extend the duration of the auction to let users know about that bid, so they can Bid too, and have a fair auction process

Updates

Lead Judging Commences

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.