MEV bots exploits or attacker is possible since deadline is absent in the SablierFlow:withdraw
function and have higher chance when transaction is in the mempool.
Here is the details:
MEV (Miner Extractable Value) attacks may occur if a pending transaction in the mempool remains open-ended, allowing malicious entities to profit off delayed transactions.
Manual Review
deadline
parameter is recommended to be used in the withdraw
function below to prevent MEV attacks on pending transactions.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.