Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Smart contract error. I managed to withdraw stkAtom tokens twice. Now I will definitely win the competition :) #38

Open
4 of 6 tasks
IgorGer55 opened this issue Jul 8, 2021 · 0 comments

Comments

@IgorGer55
Copy link

Describe the bug
Smart contract error. I managed to withdraw stkAtom tokens twice

To Reproduce
Steps to reproduce the behaviour:

  1. Go to https://gala.pstake.finance/stake
  2. Select the maximum amount. Click on unstake button
  3. Confirm the transaction in metamask.
  4. After that, do not close the service page and do not disconnect the wallet. You need to go surf other sites.
  5. After 10 minutes, they will return to the https://gala.pstake.finance/stake tab again and the funds will be debited from the staking again. I'm not sure for everyone, but it happened to me. At the same time, no confirmation was required to metamask.

Expected behaviour
The user will be delighted! He doubled his deposit + staking!

Screenshots
alt text

Desktop (please complete the following information):

  • OS: Windows 8
  • Browser Google chrome
  • Version 91.0.4472.124
  • Notebook Asus X551M

Additional context
We urgently need to solve this problem.

Ethereum address
0xCf7FB3AdC0A9A4E6F7Caff2ca8C365325Fd19277

Criticality Assessment
Please pick one:

  • High: An issue that might cause immediate loss of the funds or permanent/severe damage of the protocol state
  • Medium: An issue that might theoretically cause minimal loss of funds damage the protocol state or cause severe user dissatisfaction
  • Low: An issue that might cause user dissatisfaction or minimal failure of the application

Checklist

  • The reported issue is in the scope of the pStake BugBounty program.
  • This issue has not been reported before.
  • The ethereum address filled in is valid.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant