For sufficiently small loan values, integer division in getCalculatedFee returns a zero fee. Because flashloan does not require a positive fee, borrowers can execute unlimited small loans for free.
ThunderLoan.sol:246-250 performs integer arithmetic and rounds down. With s_flashLoanFee = 3e15, any normalized borrowed value below the threshold needed to produce one smallest token unit yields fee == 0. flashloan at lines 180-216 accepts that result and only requires repayment of principal.
The protocol provides free liquidity for small amounts and earns no yield on those operations. Attackers can repeat them or combine them with operations where small no-fee loans are economically useful.
Define a minimum fee (for example one smallest unit when amount > 0) or round fee calculation up with a documented policy. Consider a minimum borrow amount for assets where one unit is too coarse.
Test the smallest positive borrow values and assert every nonzero successful loan charges at least the configured minimum fee while ordinary-size fees remain correct.
## Description getCalculatedFee can be as low as 0 ## Vulnerability Details Any value up to 333 for "amount" can result in 0 fee based on calculation ``` function testFuzzGetCalculatedFee() public { AssetToken asset = thunderLoan.getAssetFromToken(tokenA); uint256 calculatedFee = thunderLoan.getCalculatedFee( tokenA, 333 ); assertEq(calculatedFee ,0); console.log(calculatedFee); } ``` ## Impact Low as this amount is really small ## Recommendations A minimum fee can be used to offset the calculation, though it is not that important.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.