HardhatDeFi
15,000 USDC
View results
Submission Details
Severity: low
Invalid

Referral code to Aave is hardcoded

Summary

Referral code to Aave is hardcoded, so Diva protocol cannot earn benefits from it.

Vulnerability Details

The AaveDIVAWrapper when supplying to Aave, passes hardcoded referral code = 0 (which equals to 'no referral code'), despite the referral program being disabled currently it can be introduced in the future. Considering the fact
that Diva Protocol can manage a lot of donate pools with lots of value, AaveDIVAWrapper could benefit from referral program if it would be introduced in the future. For example it can spend the earned benefits from the referral program to buy additional insurance.

Impact

If the referral program would be introduced in the future the protocol cannot earn potential benefits from that program on Aave.

Tools Used

Manual Review

Recommendations

Add owner restricted function that can adjust the referral code passed to the Aave protocol

Updates

Lead Judging Commences

bube Lead Judge 9 months ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.