Liquid Staking

Stakelink
DeFiHardhatOracle
50,000 USDC
View results
Submission Details
Severity: medium
Invalid

The `updateDeposit` vulnerable to front-running

Summary

At OperatorVCS.sol::updateDeposits at line 141 a front-running attack could occur if someone anticipates that a large deposit change is about to be processed. An attacker could attempt to manipulate fees or reward distribution based on the deposit changes.

Impact

This leads to the malicous actor getting an unfair advantage in the protocol over honest users

Recommendations

Consider introducing rate-limiting mechanisms or adding checks to ensure fairness in the order of operations when handling deposit changes and fee distribution.

Updates

Lead Judging Commences

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.