Beginner FriendlyFoundryDeFi
100 EXP
View results
Submission Details
Severity: low
Invalid

The `stake` function can be frontran just before the staking period ends

Summary

The staking period end can be frontran by a malicious user by submitting a transaction calling a function which itself calls the stake function and then the unstake function, enabling them to receive the points awards without helping bootstrap liquidity to for the ERC4626 WETH vault.

Impact

Low impact

Tools Used

Manual Review

Recommendations

Consider implementing a timelock, a fee mechanism or a combination of thereof to disincentivise such value extraction.

Updates

Lead Judging Commences

inallhonesty Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.