Proxy Factory is deployed once, the msg.sender is the owner of the factory contract and has a lot of power. It should be secure we believe. The current behavior is, any 1 individual can use EOA as an owner, which is a huge risk and we've already seen so many hacks happen in the past due to this.
owner(individual) = admin
What if the admin is not available on some days? What if the admin is sick?
They can also be subject to phishing etc.
We suggest using a multi-sig as an owner
Risk of custody of funds in 1 hand. Everyone will lose funds if the admin gets hacked or turns rogue.
Require a check in the factory's constructor such that
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.