Malicious users can steal all rewards from StabilityPool
In StabilityPool, rToken holders can stake their rToken to get deToken. When users withdraw back their rToken, holders can get some raac token rewards. The rewards that users can claim is related with users' deToken amount.
The problem here is that there is not any deposit/withdraw fee here and the rToken/deToken's exchange fee will keep 1:1. Then malicious users can repeatedly deposit/withdraw to steal all rewards.
Malicious users can steal all reward tokens in the StabilityPool contract.
Manual
Add some checkpoint for the reward distribution.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.