Skip to content

Latest commit

 

History

History
11 lines (6 loc) · 524 Bytes

014.md

File metadata and controls

11 lines (6 loc) · 524 Bytes

Attacker Can Front Run New Reward Periods and Steal Reward From Existing Stakers

Summary

When a new reward is added to the staking contract, the start time could be set to a point in the past. This is meant to reward existing stakers. However, the reward amount for those stakers is based solely on their shares, not the time staked.

This allowed an attacker to front-run any reward being added with a large sum of funds and claim a majority of the existing stakers' rewards.

Conclusion

Report was a duplicte.