
Report #29983

Report Date
April 10, 2024

Not reducing `s.recapitalisation` when users call `UnripeFacet:chop()` for UNRIPE_LP reduces the value of uncopped UNRIPE_LP

Report Info

Immunefi Response

Thank you for submitting a vulnerability report to the Beanstalk bug bounty program. We have reviewed your report and regret to inform you that we will have to close it due to inadequate proof of concept (PoC).

Immunefi review:

  • assessed impact by the triage team is in scope for the bug bounty program
  • assessed asset by the triage team is not in scope for the bug bounty program
  • The submitted PoC does not correspond to the described issue.
  • Technical Review:
    • The reported issue pertains to a different version of the contract that is Out of scope of the BBP. The PoC also relies on this version, hindering a thorough analysis of the vulnerability. We request WH to file a new submission if he believes the issue is present in the current in scope version of the protocol.

To ensure the proper escalation and evaluation of your report, Immunefi has checked the PoC to see if it matches the assessed impact and bug description, as well as verified the accuracy of your claims.

Please note that the project's team will receive a report of the closed submission and may choose to re-open it at their discretion. However, they are under no obligation to do so.