Description:
The _handleTokenOperations function transfers _collateralAmount from the user and mints an equivalent amount of wToken. However, if the collateral token charges transfer fees or is deflationary (e.g., reduces balances on transfer), the actual received amount by the contract will be less than _collateralAmount. Subsequent calls to Aave's supply with _collateralAmount will fail due to insufficient balance, causing transaction reverts. Even if the transfer succeeds but the actual amount is lower, minting wToken for the original _collateralAmount would create an imbalance between wToken supply and Aave's aToken balance, leading to undercollateralization.
Affected Files:
AaveDIVAWrapperCore.sol (specifically _handleTokenOperations function)
Impact:
Transactions involving fee-on-transfer tokens will revert, rendering the contract incompatible with such tokens.
If somehow the supply succeeds with reduced amounts, wToken would be over-minted, causing redemption failures and loss of user funds.
Recommendation:
Modify _handleTokenOperations to calculate the actual received collateral amount after transfer:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.