Skip to content

Latest commit

 

History

History
26 lines (22 loc) · 843 Bytes

Sponsorship front-running.md

File metadata and controls

26 lines (22 loc) · 843 Bytes

If proposal submission and sponsorship are done in 2 different transactions, it’s possible to front-run the sponsorProposal function by any member.

The incentive to do that is to be able to block the proposal afterwards.

Recommendation:

Pull pattern for token transfers will solve the issue. Front-running will still be possible but it doesn’t affect anything.


Slide Screenshot

032.jpg


Slide Text

  • ConsenSys Audit The Lao Finding 5.7
  • Timing & DoS
  • Major Severity
  • Front-running
  • Proposal Block
  • Pull over Push

References


Tags