complete
source
findings
Found three issues: profit accounting can be retroactively diluted by mid‑month mint/burn, unbounded month iteration can DoS transfers/withdrawals over time, and timestamp-based month boundaries are miner-influencable.
Top findings
-
medium
Mid‑month mint/burn retroactively changes the profit denominator for the entire month
-
medium
Unbounded month iteration can make transfers/withdrawals run out of gas
-
low
Month boundaries rely on `now`, allowing miner influence around cutoff times