The RustFund protocol uses unchecked arithmetic when incrementing the amount_raised
field in the contribute
function, which could potentially lead to integer overflow and incorrect fund accounting.
In the contribute
function, when a user contributes SOL to a fund, the protocol updates the total amount raised using unchecked addition:
Low
Manual Review
Add the above line of code
The max value of u64 is: 18,446,744,073,709,551,615 or around 18.4 billion SOL, given that the total supply of SOL on Solana is 512.50M, the scenario when the `contribute` function will revert due to overflow is very very unlikely to happen. Therefore, this is informational finding.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.