# Contract scan report

> **Automated scan, not an audit. Findings may be false positives; absence of findings does not mean the code is safe.**

- Scan id: `9b89d3f5-7f3d-46b1-ba97-cf2fc1ff36c4`
- Status: **ok**
- Input: source, 1 file(s), 48 nSLOC, sha256 `ff14b03492f863e5...`
- Compiler: solc 0.8.37
- Duration: 1.0 s

## Summary

| High | Medium | Low | Info |
|---|---|---|---|
| 2 | 0 | 0 | 0 |

## Findings

### F-001 [HIGH] Swap or liquidation call with minimum output hard-coded to 0

`swap-zero-min-out` (custom) · confidence medium · `swap_zero_min_out.sol:40`

```solidity
        routerV2.swapExactTokensForTokens(amount, 0, path, address(this), deadline);
```

Harvester.harvest(uint256,uint256) (swap_zero_min_out.sol#36-41) passes 0 as `amountOutMin` (no slippage protection): routerV2.swapExactTokensForTokens(amount,0,path,address(this),deadline) (swap_zero_min_out.sol#40)

**Why it matters:** A call into a DEX router or pool passes the literal 0 as its minimum-output (slippage) argument, for example amountOutMin, amountOutMinimum, minAmountOut or min_dy. Without a slippage bound the swap accepts any price, so an MEV searcher can sandwich the transaction: move the price before it, let the contract swap at a terrible rate, and move it back afterwards, extracting most of the value. Calls that run automatically (harvests, compounding, liquidations, rebalances) are particularly exposed because anyone can trigger them at a chosen moment.

**Fix:** Accept a caller-supplied minimum output, or derive one from a trusted oracle price minus a bounded slippage tolerance, and pass it to the swap.

### F-002 [HIGH] Swap or liquidation call with minimum output hard-coded to 0

`swap-zero-min-out` (custom) · confidence medium · `swap_zero_min_out.sol:44`

```solidity
        return routerV3.exactInputSingle(ISwapRouter.ExactInputSingleParams({
            tokenIn: reward,
            tokenOut: want,
            fee: 3000,
            recipient: address(this),
            deadline: deadline,
```

Harvester.harvestV3(uint256,uint256) (swap_zero_min_out.sol#43-54) passes 0 as `amountOutMinimum` (no slippage protection): routerV3.exactInputSingle(ISwapRouter.ExactInputSingleParams({tokenIn:reward,tokenOut:want,fee:3000,recipient:address(this),deadline:deadline,amountIn:amount,amountOutMinimum:0,sqrtPriceLimitX96:0})) (swap_zero_min_out.sol#44-53)

**Why it matters:** A call into a DEX router or pool passes the literal 0 as its minimum-output (slippage) argument, for example amountOutMin, amountOutMinimum, minAmountOut or min_dy. Without a slippage bound the swap accepts any price, so an MEV searcher can sandwich the transaction: move the price before it, let the contract swap at a terrible rate, and move it back afterwards, extracting most of the value. Calls that run automatically (harvests, compounding, liquidations, rebalances) are particularly exposed because anyone can trigger them at a chosen moment.

**Fix:** Accept a caller-supplied minimum output, or derive one from a trusted oracle price minus a bounded slippage tolerance, and pass it to the swap.
