Tadle

Tadle
DeFiFoundry
27,750 USDC
View results
Submission Details
Severity: low
Valid

Incorrect accounting lable in `settleAskMaker()`

Vulnerability Details 🔍 && Impact 📈

At DeliveryPlace.sol at settleAskMaker(), makerRefundAmount is uesed in addTokenBalance() with the type TokenBalanceType.SalesRevenue. It should be TokenBalanceType.MakerRefund.

Coudnt find any negative consequence on the users as SalesRevenue and MakerRefund both have the same collateral units. Impact is incorrect state handling.


Recommendations 🎯

Track it as MakerRefund, the line is here


Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

finding-DeliveryPlace-settleAskMaker-addTokenBalance-wrong-TokenBalanceType

Valid low severity, while the token type inputted is wrong, userTokenBalanceMap is still incremented appropriately, so users can still withdraw their funds. So this would technically only affect accounting and public view functions.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!