Description: The addLiquidity function in AaveDIVAWrapperCore performs multiple token operations (transfer, supply to Aave, mint) without slippage protection or atomicity guarantees.
Impact:
MEV bots could sandwich attack transactions
Users might receive fewer tokens than expected
Potential for significant financial loss
Recommended Mitigation:
Add minimum output amount parameters
Consider implementing a commit-reveal scheme
Add deadline parameters
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.