The StrategyArb
and StrategyOp
contracts approve type(uint256).max
of the underlying
tokens for the router
but never revoke allowances when setting new routers.
There are only approves for new routers but no revokes from old routers:
This issue can cause asset losses in case the previous router
address becomes malicious.
Manual Review
Consider revoking allowances from previous routers when new routers are set.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.