sherlock-audit / 2024-02-jala-swap-judging

6 stars 4 forks source link

goluu - Attack Due To Rounding Error #223

Closed sherlock-admin2 closed 6 months ago

sherlock-admin2 commented 6 months ago

goluu

high

Attack Due To Rounding Error

Summary

Rouding error attack is possible Though dead shares have been transferred in Address(0)

Vulnerability Detail

Impact

Loss of the user funds although the attacker loss his funds

Code Snippet

https://github.com/sherlock-audit/2024-02-jala-swap/blob/main/jalaswap-dex-contract/contracts/JalaPair.sol#L147

Tool used

Manual Review

Recommendation

Track transaction When new pair create.

Duplicate of #28