M-05 MitigationConfirmed #27
Labels
confirmed for report
This issue is confirmed for report
mitigation-confirmed
MR-M-05
satisfactory
satisfies C4 submission criteria; eligible for awards
Lines of code
Vulnerability details
Users can potentially control their losses because the
era
anddraftEra
can be increased independently in theseizeRSR
function.Mitigation
To mitigate this,
governance
can call theresetStakes
function when thedraftRate
exceeds thesafe range
.This allows the
governor
to reset both thestakeRate
anddraftRate
to1
simultaneously, preventing users from manipulating their losses.While this is not a perfect solution, as it relies on the governor properly executing the function, the likelihood and impact of the issue are low.
Therefore, I have marked it as confirmed
The text was updated successfully, but these errors were encountered: