DeFiFoundrySolidity
16,653 OP
View results
Submission Details
Severity: medium
Invalid

Oracle Manipulation Mitigation in _swapUnderlyingToAsset

Summary

The _swapUnderlyingToAsset function in the StrategyMainnet contract lacks proper Oracle manipulation mitigation, making it vulnerable to price manipulation attacks.

Vulnerability Details

The function does not use a robust mechanism like TWAP (Time-Weighted Average Price) to check prices, making it susceptible to price manipulation attacks.

Impact

The strategy can incur significant losses if prices are manipulated during swaps.

Tools Used

Manual Review

Recommendations

Implement TWAP or another robust mechanism to check prices.

Updates

Appeal created

inallhonesty Lead Judge 8 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.