This happens due to the usage of veRAAC
token supply in the rewards calculation
Imagine the following scenario:
User wants to claim rewards
Malicious user has a big supply of RAAC tokens and sees the tx in the mempool
He frontruns with minting veRAAC
tokens, hence increasing the veRAAC
total supply
This will lower the rewards of other users and let the malicious user get some of those rewards, practicaly stealing from ordinary users. This can be done because the `veRAAC` tokens total supply is one of the main components for computing the reward share for users as can be seen here:
This can also be done by extending a lock, which makes it even easier
User can steal the RAAC
token rewards of other users. This also impact the required quorum in the Governance
contract
Manual review
Input a slippage protection for the rewards receiving
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.