The RaccToken Reward mechanism in StabilityPool.sol
could be exploited.
A vulnerability has been identified in https://github.com/Cyfrin/2025-02-raac/blob/main/contracts/core/pools/StabilityPool/StabilityPool.sol smart contract that allows malicious users to exploit the RAAC rewards distribution mechanism. The vulnerability enables attackers to perform quick deposit-withdraw cycles to unfairly claim RAAC rewards without maintaining a meaningful stake in the pool.
Affected Function
}
Diminished rewards for legitimate long-term stakers
Potential economic damage to the protocol
Undermining of the intended staking incentive mechanism
manual review
You can Implement minimum staking duration.
Implement time-weighted reward distribution
Implement withdrawal TimeLock
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.