Both the deposit
and the withdraw
functions use raw ERC20 transfers without verifying success. Tokens that return false
instead of reverting can be exploited to manipulate balances.
manual
Use openzeppelin SafeERC20
Use SafeERC20
LightChaser Low-60
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.