Approving curveVault
without resetting the allowance could allow residual usage in the RAAC protocol.
When approving curveVault
, not resetting the allowance first could leave residual allowances that might be exploited if the vault turns malicious.
This issue poses a low risk but could lead to unauthorized token transfers if a malicious vault takes advantage of the residual allowances.
Manual review
Use safeIncreaseAllowance
in vault interactions to manage allowances securely.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.