DeFiFoundry
50,000 USDC
View results
Submission Details
Severity: low
Invalid

Not assigning `PerprtualVualt::counter` to a local var in `PerprtualVualt::deposit` can prevent `depositor` from getting his shares

Summary

In PerprtualVualt::deposit the global var PerprtualVualt::counteris increased by 1 without assigning to a local var and this serves as the depositors usersID in depositInfomapping.

Vulnerability Details

In PerprtualVualt::deposit the global var PerprtualVualt::counteris increased by 1 without assigning to a local var and this serves as the depositors usersID in depositInfomapping. Since var is not assigned to a local var, if a large deposit call was made slightly before it and the large deposit has now incremented the global var, the large depositor might not get his due shares.

Impact

Depositor might not get due shares.

Tools Used

Manual Review.

Recommendations

Assign PerprtualVualt::counter to a local var in PerprtualVualt::deposit

Updates

Lead Judging Commences

n0kto Lead Judge 9 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality
Assigned finding tags:

Suppositions

There is no real proof, concrete root cause, specific impact, or enough details in those submissions. Examples include: "It could happen" without specifying when, "If this impossible case happens," "Unexpected behavior," etc. Make a Proof of Concept (PoC) using external functions and realistic parameters. Do not test only the internal function where you think you found something.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!