Part 2

Zaros
PerpetualsDEXFoundrySolidity
70,000 USDC
View results
Submission Details
Severity: high
Invalid

Missing Pause & Unpause Mecchanism in Zaro's Protocol

Summary

The Zaros Perpetuals DEX lacks a pause and unpause mechanism, which is crucial security feature for any DEFi protocol. This absence exposes the protocol to significant risks in case of an emergency, exploit , or unexpected market event.

Vulnerability Details

A pause mechanism allows the protocol's admin (or governance) to halt trading, deposits, liquidations, and other critical functions in case of

  1. A major security exploit: (e.g., an oracle manipulation attack or smart contract vulnerability).

  2. Sequencer downtime which is taking longer

  3. A chainlink failure or sequencer downtime on Arbitrum, preventing inaccurate prices incorrect liquidation and unfair liquidations

Impact

  • Smart Contract exploit

  • Oracle manipulation attacks

  • Liquidity drain risks

  • Unexpected market crashes

Tools Used

Manual Review

Recommendations

Zaros developers should immediately implement a pause function in both:

  1. The perpetuals Trading Engine

  2. The Market Making Engine

Updates

Lead Judging Commences

inallhonesty Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Design choice

Appeal created

olami9783 Submitter
10 months ago
inallhonesty Lead Judge
10 months ago
inallhonesty Lead Judge 9 months ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!