RAAC reward calculation is not time-based and depends only on userDeposit and can be abused by frequent withdraw() calls.
RAAC reward calculation is not time-based and depends only on userDeposit:
Malicious user can abuse this by first depositing large amounts of RToken, then calling withdraw() with deCRVUSDAmount = 1 multiple times, and his rewards will be calculated during every call using almost unchanged userDeposits value.
User can steal all RAAC tokens from stability pool.
Manual review.
Calculate rewards based on duration of user deposit and resets user rewards to 0 after rewards was claimed.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.