Beanstalk Immunefi Committee
Reward 10,000 Beans to the whitehat that reported the issue that Chopping Unripe LP does not decrease the recapitalization target.
Currently, when Unripe LP holders Chop, s.recapitalized
is unchanged. As a result, the Barn Raise ends earlier than intended, i.e., Beanstalk will not sell enough Fertilizer to fully recapitalize all Unripe LP.
Decrement s.recapitalized
by an amount proportional to the underlying Ripe assets removed upon Chop.
Given that the issue is low impact and not realized until the end of the Barn Raise, the BCM determined that an EBIP is not necessary. The goal is to include this fix in an upcoming BIP.
Given that the bug is not exploitable and only results in returning less value than intended to users at the end of the Barn Raise, the most accurate impact in scope is "Contract fails to deliver promised returns, but doesn't lose value", i.e., Medium severity.
Although the impact is low, given the high likelihood of the vulnerability presenting itself later in the Barn Raise, the BIC has determined that this bug report be rewarded 10,000 Beans. The Beans were sent from the Immunefi Vault.
- Potential practicable economic damage: N/A
- Impact: Medium — Contract fails to deliver promised returns, but doesn't lose value
- Entitled to reward: Yes