Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: high
Valid

Malicious user can claim more fee awards than they deserve (sniping attack)

Summary

Malicious user can claim more fee awards than they deserve

Vulnerability Details

Because of broken formula in _calculatePendingAwards fn, late users will receive more than expected awards.

So attacker will wait until totalDistributed is large:

  • Deposits large amount to get high voting power briefly

  • Claims rewards based on current VP ratio

  • Withdraws immediately

Impact

Malicious users can drain funds from the fee service contract

Tools Used

Manual review

Recommendations

Updates

Lead Judging Commences

inallhonesty Lead Judge about 2 months ago
Submission Judgement Published
Validated
Assigned finding tags:

StabilityPool::calculateRaacRewards is vulnerable to just in time deposits

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.