58488 sc low tokeautousdstrategy claims rewards to itself automatically when deallocate is called but since reward token is tokemak the rewards remain permanently locked
Description
Brief/Intro
//From TokeAutoUSDStrategy::_deallocate()...
// withdraw shares, claim any rewards
rewarder.withdraw(address(this), sharesNeeded, true);//From MainRewarder _withdraw
if (claim) {
_processRewards(account, account, true);
}Vulnerability Details
Impact Details
References
Proof of Concept
Proof of Concept
Previous56365 sc critical liquidation fee overdraft drains pooled collateralNext58019 sc high flawed killswitch implementation in mytstrategy leads to permanent loss of funds
Was this helpful?