code-423n4 / 2021-05-yield-findings

0 stars 0 forks source link

function redeem should return 'redeemed' amount #58

Open code423n4 opened 3 years ago

code423n4 commented 3 years ago

Handle

pauliax

Vulnerability details

Impact

function redeem in contract FYToken should return 'redeemed' amount. There return value is not used anywhere, but it's a mistake that it assigns 'redeemed' but returns 'amount'.

Recommended Mitigation Steps

Remove return sentence or explicitly return 'redeemed'.