Liquid Staking

Stakelink
DeFiHardhatOracle
50,000 USDC
View results
Submission Details
Severity: medium
Invalid

ABSENCE OF SLIPPAGE PROTECTION CAUSES LINK DEPOSIT DISREPANCIES

Summary

The PriorityPool:_depositLiuidityTokens function lacks slippage protection, which can result in differences between the expected and actual amounts deposited.

Vulnerability Details

The function deposits tokens into the strategy pool without accounting for potential slippage. As a result, the actual stLINK amount received may differ from the anticipated amount, leading to inconsistencies in the number of shares allocated to the user.

Impact

If market conditions change before the transaction processes, the user could get a much worse swap.

Tools Used

Manual Review

Recommendations

Allow users to specify a slippage tolerance. This protects the user from executing a transaction in unfavorable conditions.

Updates

Lead Judging Commences

inallhonesty Lead Judge 11 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.