Anyone can modify the yields.
This means that anyone can modify yields, and gain more than set by authenticated admins.
https://github.com/Cyfrin/2023-09-ditto/blob/a93b4276420a092913f43169a353a6198d3c21b9/contracts/facets/YieldFacet.sol#L41C1-L73C6
Loss of Yields
Manual Review
Create a Role Based Access Control for admins
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.