DeFiFoundry
50,000 USDC
View results
Submission Details
Severity: low
Invalid

Inefficient Idle Fund Detection Leading to Capital Underutilization

Summary

The _isFundIdle function uses an overly simplistic check that only considers raw collateral token balance against minDepositAmount. This implementation fails to account for fragmented balances and trapped funds below the minimum threshold, leading to capital inefficiency.

Vulnerability Details

function _isFundIdle() internal view returns (bool) {
if (collateralToken.balanceOf(address(this)) >= minDepositAmount) {
return true;
} else {
return false;
}
}

The current implementation of the _isFundIdle function does not take into account fragmented balances from multiple deposits, accumulated funding fees, remaining amounts from position closures, and post-liquidation balances.

The root of the problem comes from using minDepositAmount as a hard threshold to detect idle funds. This causes if balance < minDepositAmount, the funds cannot be used for new positions.

Impact

Funds trapped due to being less than minDepositAmount cannot be used for new positions.

Tools Used

  • Manual review

Recommendations

Implement auto-compounding for fragmented balances.

Updates

Lead Judging Commences

n0kto Lead Judge 7 months ago
Submission Judgement Published
Invalidated
Reason: Design choice
Assigned finding tags:

Informational or Gas

Please read the CodeHawks documentation to know which submissions are valid. If you disagree, provide a coded PoC and explain the real likelihood and the detailed impact on the mainnet without any supposition (if, it could, etc) to prove your point.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.