code-423n4 / 2021-12-pooltogether-findings

0 stars 0 forks source link

Support of deflationary / rebasing tokens #140

Closed code423n4 closed 2 years ago

code423n4 commented 2 years ago

Handle

pauliax

Vulnerability details

Impact

Deflationary (fee on transfer) / rebasing tokens are not supported. Because anyone can createPromotion with an arbitrary token, such tokens may be lost forever.

Recommended Mitigation Steps

Consider checking the actual amounts transferred (balance before/after) if you want to include such tokens in promotions.

PierrickGT commented 2 years ago

Duplicate of https://github.com/code-423n4/2021-12-pooltogether-findings/issues/30