code-423n4 / 2021-04-marginswap-findings

1 stars 0 forks source link

[INFO] liquidators may be a subject of front-running attacks #53

Open code423n4 opened 3 years ago

code423n4 commented 3 years ago

Vulnerability details

This is FYI, not a real issue as you have expressed your interest in minor improvement suggestions (not security or gas related):

/// 3) Liquidators may not call from a contract address, to prevent extreme forms of /// of front-running and other price manipulation. Doesn't this mean that liquidators are a subject of front-running attacks? Bots can monitor the liquidation txs and replicate them by sending the same tx data from their EOA.

Email address

pauliax6@gmail.com

Handle

paulius.eth

Eth address

0x523B5b2Cc58A818667C22c862930B141f85d49DD

werg commented 3 years ago

Yes, this is an unfortunate cost of using the current stock of AMMs. Hence we can only use well-capitalized pairs. Future versions will deal with this more cleanly.