Summary
boostState.minBoost is set to a flawed value 1e18, bigger then boostState.maxBoost(25000), when _applyBoost() is called, BoostCalculator.calculateBoost() will always revert.
Vulnerability Details
When deployed, boostState.minBoost is set to 1e18, boostState.maxBoost is set to 25000, which means:
boostState.minBoost > boostState.maxBoost.
constructor(
address _rewardToken,
address _stakingToken,
address _controller,
uint256 _maxEmission,
uint256 _periodDuration
) {
rewardToken = IERC20(_rewardToken);
stakingToken = IERC20(_stakingToken);
controller = _controller;
_grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
_grantRole(CONTROLLER_ROLE, _controller);
boostState.maxBoost = 25000;
boostState.minBoost = 1e18;
...
}
getUserWeight() is a public function, in this function, _applyBoost() is called, in function _applyBoost(), BoostCalculator.calculateBoost() will be called to calculate the boost value.
function _applyBoost(address account, uint256 baseWeight) internal view virtual returns (uint256) {
if (baseWeight == 0) return 0;
IERC20 veToken = IERC20(IGaugeController(controller).veRAACToken());
uint256 veBalance = veToken.balanceOf(account);
uint256 totalVeSupply = veToken.totalSupply();
BoostCalculator.BoostParameters memory params = BoostCalculator.BoostParameters({
maxBoost: boostState.maxBoost,
minBoost: boostState.minBoost,
boostWindow: boostState.boostWindow,
totalWeight: boostState.totalWeight,
totalVotingPower: boostState.totalVotingPower,
votingPower: boostState.votingPower
});
uint256 boost = BoostCalculator.calculateBoost(
veBalance,
totalVeSupply,
params
);
return (baseWeight * boost) / 1e18;
}
in calculateBoost(), boostRange is calculated as following:
uint256 boostRange = params.maxBoost - params.minBoost;
since params.maxBoost < params.minBoost, will revert.
function calculateBoost(
uint256 veBalance,
uint256 totalVeSupply,
BoostParameters memory params
) internal pure returns (uint256) {
if (totalVeSupply == 0) {
return params.minBoost;
}
uint256 votingPowerRatio = (veBalance * 1e18) / totalVeSupply;
uint256 boostRange = params.maxBoost - params.minBoost;
uint256 boost = params.minBoost + ((votingPowerRatio * boostRange) / 1e18);
if (boost < params.minBoost) {
return params.minBoost;
}
if (boost > params.maxBoost) {
return params.maxBoost;
}
return boost;
}
Impact
getUserWeight() will always revert.
Tools Used
manually reviewed
Recommendations
set boostState.minBoost to a resonable value, maybe 10000.