Decimals are not required in the deposit function
Decimal handling on deposit was unconstrained, allowing values that the backend may not handle cleanly and creating drift between the displayed amount and the on-chain settlement.
Description
The deposit function did not require or enforce a specific decimal format. Users could enter decimal values that the application accepted at the UI layer, but the backend was not necessarily designed to handle the resulting partial values cleanly. This mirrors the decimal-rounding class observed across the Virtual Rollups game audits (All Your Base, Beecasino, Dedprz).
Impact
Display drift between the UI's decimal representation and any backend numeric handling. Potential gas griefing or settlement failures if the on-chain layer rejects decimal-tail values.
Recommendation
Decide whether decimals are required for deposits. If not, reject them at the input boundary; if so, normalize to a fixed-precision representation that the backend explicitly supports, and use that canonical numeric format end-to-end.
Hopium: Acknowledged. Zealynx: Acknowledged.