DeFiFoundry
20,000 USDC
View results
Submission Details
Severity: low
Invalid

Allowing 0 amount auction may lead users who participate bidding to loss their FjordPoints

Summary

FjordAucion.sol contructor doesn't check _totalTokens, which allows 0 amount auction may lead users who participate bidding to loss their FjordPoints

Vulnerability Details

constructor(
address _fjordPoints,
address _auctionToken,
uint256 _biddingTime,
uint256 _totalTokens
) {
if (_fjordPoints == address(0)) {
revert InvalidFjordPointsAddress();
}
if (_auctionToken == address(0)) {
revert InvalidAuctionTokenAddress();
}
fjordPoints = ERC20Burnable(_fjordPoints);
auctionToken = IERC20(_auctionToken);
owner = msg.sender;
auctionEndTime = block.timestamp.add(_biddingTime);
totalTokens = _totalTokens;
}

Impact

Users who participate bidding may loss their FjordPoints

Tools Used

manual

Recommendations

check if _totalTokens > 0

Updates

Lead Judging Commences

inallhonesty Lead Judge 9 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.