The OrderBranch
executes market orders without slippage parameters, allowing keepers to sandwich users.
Affected Code:
Exploit Scenario:
User submits order to buy 100 ETH at market price.
Keeper front-runs with large ETH buy, increasing price.
User receives 90 ETH instead of 100.
User Fund Loss: 10-30% per trade.
Medium Severity (CVSS 7.1).
Tenderly transaction simulation.
Historical price data analysis.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.