QuantAMM

QuantAMM
49,600 OP
View results
Submission Details
Severity: medium
Invalid

During recovery mode balancer bypasses hooks, nfts burning is not happening in UpliftOnlyExample

Summary

In the UpliftOnlyExample, which is built on top of Balancer, when the pool enters recovery mode, the essential hooks that should burn user NFTs and update fee data are completely bypassed. It is bcz during recovery mode, balancer bypasses hooks. This flaw allows users to perform emergency withdrawals without their NFTs being destroyed or their fee records being updated. Consequently, users can withdraw their funds multiple times using the same NFT, leading to potential double withdrawals and inaccurate fee tracking within the system.

Impact

Users can exploit the emergency withdrawal function to withdraw funds multiple times by bypassing NFT burning and fee updates.

Recommendation

Ensure that all critical hooks, such as NFT burning and fee data updates, are executed even during recovery mode to prevent unauthorized multiple withdrawals.

Updates

Lead Judging Commences

n0kto Lead Judge 7 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Appeal created

0xtheblackpanther Submitter
7 months ago
n0kto Lead Judge
6 months ago
n0kto Lead Judge 6 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.