20,000 USDC
View results
Submission Details
Severity: low

Lack of staking contract address update in Fees contract

Summary

There is no way to update the staking contract in the Fees contract.

Vulnerability Details

Lets say there is a vulnerability in the staking contract and it cannot receive any funds anymore.
There is no way to change it in the Fees contract as it's always sending the WETH balance to the initialized staking contract at the end of the sellProfits function.

Impact

Potentially loss of funds

Tools Used

Manual review

Recommendations

Add a setStakingContract function

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!