A vulnerabilty stems in _redeemLiquidity and _redeemPositionToken use transferFrom() for DIVA position tokens without validating the return value.
This vulnerability will allow tokens with false on failure instead of revert to bypass critical transfer logic, which can potentially allow malicious users to steal funds.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.