RAAC tokens deposited through the depositRAACFromPool function in the StabilityPool contract, which are intended for manager rewards, incorrectly become part of the general reward pool and can be claimed by regular users due to unimplemented manager distribution logic.
RAAC tokens from the liquidity pool are meant to be distributed to managers based on their allocations:
However, these tokens are added to the StabilityPool's RAAC balance and become claimable by regular users through the reward calculation:
High: RAAC tokens intended for manager rewards are incorrectly distributed to regular users. This breaks the intended incentive mechanism for managers and could lead to loss of manager rewards.
Consider separating manager rewards from user rewards by using a dedicated manager reward tracking system.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.