Algo Ssstablecoinsss

First Flight #30
Beginner FriendlyDeFi
100 EXP
View results
Submission Details
Severity: low
Invalid

Re-entrancy attacks could be possible if `WETH` or `WBTC` contracts get upgraded or go rogue

Vulnerability Details

Both tokens used for collateral are upgradeable, and in case they go rogue or get upgraded with malicious functionality, they open up re-entrancy attacks in several functions. For example, an attacker could call DSCEngine__liquidate and start liquidating all the users that have lower health factor and absorb all the collateral without burning his own tokens.

Impact

If this situation would happen, the consequences of the protocol are disastrous. However, the likelihood is very minimal.

Tools Used

Manual review.

Updates

Lead Judging Commences

bube Lead Judge 6 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.