DeFiFoundrySolidity
16,653 OP
View results
Submission Details
Severity: medium
Invalid

Deadline Manipulation Risk

Description: In IVeloRouter, the deadline parameter can be manipulated in which No strict validation of deadline, Potential for sandwich attacks and Miners/validators can manipulate transaction timing.

Impact:

  • Potential price manipulation

  • Reduced swap execution guarantees

Proof of Concept:

function manipulateSwap(IVeloRouter router) external {
// Set extremely large deadline
router.swapExactTokensForTokens(
amount,
minOut,
routes,
recipient,
block.timestamp + 1 weeks // Excessive deadline
);
}

Recommended Mitigation:

  • Implement stricter deadline validation

  • Use shorter, more restrictive deadline windows

  • Consider using Uniswap V3 style TWAP oracles

Updates

Appeal created

inallhonesty Lead Judge 6 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality
inallhonesty Lead Judge 6 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.