The
StabilityPool
allows users todeposit
andwithdraw
in the same transaction, capturing a full share of accumulatedRAAC rewards
without meaningful participation in the protocol. This enables malicious users to extract value from the reward system without contributing to protocol stability.
The StabilityPool's
reward distribution relies on accumulated RAAC
tokens in the pool rather than time-weighted positions. So When a large deposit enters the pool, it immediately becomes eligible for all accumulated rewards proportional to its share of total deposits. With no minimum deposit duration, a malicious whale user can capture these rewards through deposit-withdraw transaction.
A whale can deposit 1e6 tokens and immediately withdraw, capturing three reward ticks worth of RAAC tokens in a single transaction.
The reward calculation is based solely on current deposit share, allowing instant reward capture.
A whale can deposit 1e6 tokens and immediately withdraw, capturing reward ticks worth of RAAC tokens in a single transaction. This creates a profitable exploit that drains reward tokens from the protocol without contributing.
Manuel review.
Implement time-weighted reward distribution.
Add minimum deposit duration requirement.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.