The GuageController:vote() function doesn't enforce MIN_VOTE_DELAY
The contract defines MIN_VOTE_DELAY(10 days) but fails to enforce it in the contract.
The vote function contains no checks against lastUpdatedTime[msg.sender], allowing unlimited voting frequency. Attackers can manipulate gauge weights through rapid vote spamming and negligible micro-votes, destabilizing reward distributions
DOS legitimate voters through gas price wars for vote inclusion
Skew RWA/RAAC reward ratios to make yield farming unsustainable
Manual review
Enforce MIN_VOTE_DELAY
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.