code-423n4 / 2024-03-pooltogether-findings

5 stars 4 forks source link

QA Report #350

Closed c4-bot-9 closed 5 months ago

c4-bot-9 commented 5 months ago

See the markdown file with the details of this report here.

raymondfam commented 5 months ago

L4 to #274 L2: Owner gets to set Liquidation pair. However, it's the Liquidation Source that's in control of liquidation and sending the net yield to Prize Pool, NOT the Prize Vault owner. L3: yieldFeePercentage isn't fixed. It can be changed via setYieldFeePercentage() L5: _yieldFee + _amountOut = total

Note: This QA report should be deemed unsatisfactory with only 1L but is kept sufficient pending for a possible upgrade from L4.

c4-pre-sort commented 5 months ago

raymondfam marked the issue as sufficient quality report

c4-judge commented 5 months ago

hansfriese marked the issue as grade-c