QuantAMM

QuantAMM
49,600 OP
View results
Submission Details
Severity: low
Invalid

bad user can frontrun the pool creator and set the rule for the pool

Summary

Vulnerability Details

https://github.com/Cyfrin/2024-12-quantamm/blob/a775db4273eb36e7b4536c5b60207c9f17541b92/pkg/pool-quantamm/contracts/UpdateWeightRunner.sol#L235

the setruleforpool function is used to set a rule for a pool

in the setruleforpool function a bad user can frontrun the pool creator and set the rule for the pool, since the setruleforpool function is callable by anyone

Impact

anyone being able to set the rule for a pool can lead to unexpected bahavior in the pool, such as incorrect pricing

Tools Used

manual

Recommendations

the poolcreater should ensure to set the rule for the pool while creating the pool or the setruleforpool function should be callable by only the pool creater to avoid being frontrunned

Updates

Lead Judging Commences

n0kto Lead Judge 11 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
Assigned finding tags:

Informational or Gas / Admin is trusted / Pool creation is trusted / User mistake / Suppositions

Please read the CodeHawks documentation to know which submissions are valid. If you disagree, provide a coded PoC and explain the real likelyhood and the detailed impact on the mainnet without any supposition (if, it could, etc) to prove your point.

Appeal created

cody Submitter
11 months ago
huntoor Auditor
11 months ago
n0kto Lead Judge
11 months ago
n0kto Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
Assigned finding tags:

Informational or Gas / Admin is trusted / Pool creation is trusted / User mistake / Suppositions

Please read the CodeHawks documentation to know which submissions are valid. If you disagree, provide a coded PoC and explain the real likelyhood and the detailed impact on the mainnet without any supposition (if, it could, etc) to prove your point.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!