code-423n4 / 2023-08-pooltogether-mitigation-findings

0 stars 0 forks source link

M-05 MitigationConfirmed #45

Open code423n4 opened 1 year ago

code423n4 commented 1 year ago

Lines of code

Vulnerability details

Issue mitigated

About the problem

In case if someone transfers balance to the SPONSORSHIP_ADDRESS, then _transferBalance function handles total balance incorrectly. This will affect frequency of prize winning.

Solution

Pool together team has fixed the issue by not allowing to transfer to SPONSORSHIP_ADDRESS. As result, attack is not possible anymore.

c4-judge commented 1 year ago

Picodes marked the issue as satisfactory