40,000 USDC
View results
Submission Details
Severity: medium
Valid

No methods to stop and replace arbiter if keys are leaked

Summary

If arbiter private keys are leaked, seller or buyer can profit from that. Currently, there is no way to replace arbiter for a new one.

Vulnerability Details

Imagine that arbiters private keys are leaked and anyone can get to them. This poses a problem where seller could get money without providing report.

There should be methods to stop arbiter from resolving dispute and nominating a new one.

Impact

When arbiter keys are leaked, seller can get tokens without providing the report.

Tools Used

Manual review

Recommendations

Implement a functionality to stop arbiter from resolving a dispute and to nominate a new one.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.