attacker could drain rewad tokens from stability pool due to its flawed reward distribution mechnism
Users deposit RToken/RcrvUSD to stability pool and get reward RAAC tokens propotional to their deposit when withdrawing, as in :
The reward amount is calculated as proportional to total RAAC balance the pool hold, where the proportion is the user deposits devided by total deposits. Notice that there is no other constrains such as deposits period as factor to contribute to reward split. Therefor an attack could monitor the reward tick() event and then deposit(or borrow) a large amount of RcrvToken to share the large portion of the totalRewards, after that he can immediately withdraw/repay his deposit, in this way, an attack could drain almost all rewards.
rewards raac token could be drained by attacker
manual
consider modifying the reward distribution mechanism
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.