Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: low
Valid

Compromise Risk Due to Immutable STADIUM_ADDRESS

Summary

There is no way to change the STADIUM_ADDRESS if it is compromised

Vulnerability Details

I understand the STADIUM_ADDRESS is immutable but this is a possible vulnerability if the this address is compromised in any way, specially in the case of the STADIUM_ADDRESS becomes blacklisted by any token, this will revert every attempt to send it the commission from any contest.

Impact

If the STADIUM_ADDRESS is compromised in any way the prize will be locked forever.

Tools Used

Manual

Recommendations

add a function controlled by an owner that can change the STADIUM_ADDRESS in case something goes wrong. maybe also add a timelock if necessary.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.