Open code423n4 opened 2 years ago
gzeon
https://github.com/Badger-Finance/badger-ibbtc-utility-zaps/blob/6f700995129182fec81b772f97abab9977b46026/contracts/IbbtcVaultZap.sol#L158 depositAmounts[i] += _amounts[i]; can be depositAmounts[i] = _amounts[i]; instead
depositAmounts[i] += _amounts[i];
depositAmounts[i] = _amounts[i];
Agree with the finding, we can just use =
=
Handle
gzeon
Vulnerability details
Proof of Concept
https://github.com/Badger-Finance/badger-ibbtc-utility-zaps/blob/6f700995129182fec81b772f97abab9977b46026/contracts/IbbtcVaultZap.sol#L158
depositAmounts[i] += _amounts[i];
can bedepositAmounts[i] = _amounts[i];
instead