DeFiFoundry
20,000 USDC
View results
Submission Details
Severity: medium
Valid

FjordAuctionFactory has no rescue/recover token ability

Summary

In FjordAuctionFactory, there is no option to withdraw the token that was mistakenly sent to the factory contract or was returned from the FjordAuction contract when no one bids for it.

Vulnerability Details

There are many cases which may cause the fund to be stuck, such as:

  • Wrong auctionToken sent to the FjordAuctionFactory contract

  • Mistakenly sent more amount of totalTokens required by the FjordAuctionFactory

  • Or simply the returned auctionToken from FjordAuction contract when the auction ends but no one bids for the token

...

Impact

Fund is permanently stuck within FjordAuctionFactorycontract.

Tools Used

Manual Analysis

Recommendations

Consider adding a function which can be used to recover the token in FjordAuctionFactorycontract.

Updates

Lead Judging Commences

inallhonesty Lead Judge 10 months ago
Submission Judgement Published
Validated
Assigned finding tags:

If no bids are placed during the auction, the `auctionToken` will be permanently locked within the `AuctionFactory`

An auction with 0 bids will get the `totalTokens` stuck inside the contract. Impact: High - Tokens are forever lost Likelihood - Low - Super small chances of happening, but not impossible

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.