Tadle

Tadle

Tadle

DeFi
30,000 USDC
Submission Details
Severity: medium
Valid

Platform Fees Can Be Bypassed for Low Decimal Standard ERC20 Tokens

Updates

Lead Judging Commences

0xnevi Lead Judge 26 days ago
Submission Judgement Published
Validated
Assigned finding tags:

finding-PreMarkets-tradeTax-round-down-low-decimal

Valid medium, this will indeed cause a leakage (albeit requires relatively small amount of collateral transacted, and is most significant for lower decimal tokens (does not break ERC20 specifications), resulting in platFormFee rounding to zero and creater of offers not sending fees to capitalPool when `_depositTokenWhenCreateTaker` is invoked. For issues noting rounding directions, it will be low severity given the impact is not proven sufficiently with a PoC/numerical example and most rounding will not result in significant losses. I believe the most appropriate solution here is to increase scale of platFormFees scalar, but to make sure that overflows are considered for higher decimal tokens.

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.