Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: medium

No recovery function in the proxy

Summary

If the implementation address was set incorrectly due to an error, and the sponsors donate to this address, it is not possible to retrieve these tokens back.

Vulnerability Details

  1. The owner creates a contest and makes a mistake in the implementation address.

  2. The sponsors donate to the proxy.

  3. The organizer deploys the proxy and tries to distribute the tokens to the winners.

  4. The proxy with the incorrect implementation address cannot call the distributor.

  5. Funds are stuck in the proxy and cannot be recovered.

Impact

Funds can get stuck in the proxy and can not be recovered anymore

Tools Used

Manual Review, AuditWizard

Recommendations

There should be a recovery function that is directly implemented on the proxy and does not rely on the distributor.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.