code-423n4 / 2021-04-marginswap-findings

1 stars 0 forks source link

Events not indexed #27

Open code423n4 opened 3 years ago

code423n4 commented 3 years ago

Email address

mail@cmichel.io

Handle

@cmichelio

Eth address

0x6823636c2462cfdcD8d33fE53fBCD0EdbE2752ad

Vulnerability details

The CrossDeposit, CrossTrade, CrossWithdraw, CrossBorrow, CrossOvercollateralizedBorrow events in MarginRouter are not indexed.

Impact

Off-chain scripts cannot efficiently filter these events.

Recommended mitigation steps

Add an index on important arguments like trader.