The delegateBoost
function in BoostController.sol
allows users to delegate their boost to multiple addresses without reducing their delegatable power, enabling infinite reuse of the same boost amount.
The delegateBoost
function records delegations without tracking or reducing the delegator's available boost power. This allows a user to delegate the same boost amount multiple times, effectively multiplying their influence in the protocol.
Proof of Concept (Simplified):
Users can infinitely multiply their boost power through multiple delegations
Severely distorts voting power and reward distribution mechanisms
Compromises protocol governance and economic incentives
Early exploiters could gain disproportionate control over protocol decisions
Manual Review
Track and enforce delegation limits.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.