This repository has been archived by the owner on Dec 20, 2024. It is now read-only.
Frequently bumping to increase earning power may eat depositor rewards #42
Labels
Low/Info
A Low/Info severity issue.
Description
The bump mechanism is intended to incentivize keepers to update depositors earning power in exchange for a fee. We can see that in the case the earning power is increased, the keeper can take the whole rewards intended for the depositor :
GovernanceStaker.sol#L489-L491:
The only constraint is that
_requestedTip
should be lower thanmaxBumpTip
.GovernanceStaker.sol#L473:
Impact
Depositor rewards are stolen by keepers
Recommendation
Multiple mitigations may envisioned:
_isQualifiedForBump
calculation in the calculator in order to rate limit bumpingThe text was updated successfully, but these errors were encountered: