Despite access control restrictions, the GaugeController allows gauge admins to modify type weights without any time delay or change magnitude limits. This enables potential manipulation of reward distributions through rapid weight changes.
The setTypeWeight function has admin-only access:
These weights directly affect reward calculations:
Problems:
No minimum delay between weight changes
No limits on change magnitude
Changes take effect immediately
No gradual transition period
Reward Manipulation: Admin can front-run (unintentionally) reward distributions with weight changes
Manual code review
Implement time delay for weight changes
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.