Description: In IAlchemist
, the YieldTokenConfig
includes maximumLoss
and maximumExpectedValue
, which could be vulnerable to oracle manipulation.
Impact:
Potential economic exploit
Incorrect value calculations
Risk of unexpected protocol behavior
Recommended Mitigation:
Use decentralized price feeds
Implement time-weighted average price (TWAP) mechanisms
Add multiple oracle sources
Implement circuit breakers
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.