H-04 MitigationConfirmed #58
Labels
edited-by-warden
mitigation-confirmed
MR-H-04
satisfactory
satisfies C4 submission criteria; eligible for awards
Lines of code
Vulnerability details
C4 Issue
H-04: code-423n4/2024-04-renzo-findings#326
Issue Details
Issue of this vuln come from withdraw mechanism. When withdrawal amount is calculated at withdrawal request submission time instead of at withdrawal claim time:
Along with there is no fee in deposit and withdraw, which can lead to arbitrage risk.
Mitigation
Solution to mitigate is good enough to fix the issue. This design is also used in other protocols.
Conclusion
Mitigation confirmed.
The text was updated successfully, but these errors were encountered: