code-423n4 / 2023-05-asymmetry-mitigation-findings

2 stars 2 forks source link

Mitigation Confirmed for H-01 #3

Open code423n4 opened 1 year ago

code423n4 commented 1 year ago

Fix looks good. Root cause of issues was that balance() returned the ERC20.balanceOf() the underlying derivatives contracts, allowing attackers to manipulate it via donation. Now the contracts use internally tracked balances that can't be manipulated.

c4-judge commented 1 year ago

Picodes marked the issue as satisfactory