HardhatDeFi
15,000 USDC
View results
Submission Details
Severity: high
Invalid

Potential MEV Attack in `addLiquidity` Function

Description: The addLiquidity function in AaveDIVAWrapperCore performs multiple token operations (transfer, supply to Aave, mint) without slippage protection or atomicity guarantees.

Impact:

  • MEV bots could sandwich attack transactions

  • Users might receive fewer tokens than expected

  • Potential for significant financial loss

Recommended Mitigation:

  • Add minimum output amount parameters

  • Consider implementing a commit-reveal scheme

  • Add deadline parameters

Updates

Lead Judging Commences

bube Lead Judge 9 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.