The owner
role has a single point of failure and onlyOwner
can use critical functions, posing a centralization issue.
Having a single EOA as the only owner of contracts is a large centralization risk and a single point of failure. A single private key may be taken in a hack, or the sole holder of the key may become unable to retrieve the key when necessary.
There is always a chance for owner
keys to be stolen, and in such a case, the attacker can cause damage to the project due to important functions.
Manual Code Review
Consider changing to a multi-signature setup, or having a role-based authorization model.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.