40,000 USDC
View results
Submission Details
Severity: medium

Potential Design Issue with `buyerAward`

Summary

Potential Design Issue with buyerAward

Vulnerability Details

buyerAward can be set with any value by Arbiter without the agreement.

Impact

When Arbiter is compromised, the buyer will not get the token back.

Tools Used

Manual

Recommendations

May need an extra stage to allow both buyer and seller agree about the cost.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.