code-423n4 / 2023-07-pooltogether-findings

12 stars 7 forks source link

Upgraded Q -> 2 from #392 [1689707598962] #477

Closed c4-judge closed 11 months ago

c4-judge commented 11 months ago

Judge has assessed an item in Issue #392 as 2 risk. The relevant finding follows:

4 - The liquidator can be frontrunned while is depositing prizeTokens to the prizePool The liquidator should introduce prizeTokens to the prizePool before he calls the Vault.liquidate() function. The problem is that a malicious actor can be frontrunned and make the introduced prizeTokens to be accumulated to another vault. The liquidator can lost his prizeTokens.

c4-judge commented 11 months ago

Picodes marked the issue as duplicate of #295

c4-judge commented 11 months ago

Picodes marked the issue as unsatisfactory: Invalid