Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: medium
Valid

Funds Loss

Summary

There’s lies a potentially vulnerability, docs says that only organizer can distribute funds that leads to the rug pull vector.

Vulnerability Details

Suppose organizer starts the contests and supporters solves the problem then organizer tranfers the funds to his account. And the worst case scenario is that when sponsers sponsering the funds, organiser set the contest, supporters solves the problem and organiser transfer the funds into his own malicious accounts. So, the organizer rug pull both the supporter and sponsers.It is written on the contest page that organizer can only distribute funds

Impact

There is somehow centerlization of the funds and organizer can do fruad.

Tools Used

Manual

Recommendations

There should be changes in the code such a way that some rules are been set and funds are transfers to supporter automatically according to there participation in the project.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.