Liquid Staking

Stakelink
DeFiHardhatOracle
50,000 USDC
View results
Submission Details
Severity: medium
Invalid

Anyone can bypasses `rewardThreshold` amount and withdraw fee before it reaches the required amount.

Summary

In a contract named LSTRewardsSplitter, function named splitRewards bypasses rewardThreshold which is on purpose but, there is no restriction on it which means that anyone anytime can bypass the required rewardThreshold.

Vulnerability Details

If anyone can bypass rewardThreshold, this means that the functionality of a LSTRewardsSplitter can be compromised anytime or even every time.

Impact

Medium

Tools Used

Manual review.

Recommendation

N/A

Updates

Lead Judging Commences

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.