DittoETH

Ditto
DeFiFoundryOracle
55,000 USDC
View results
Submission Details
Severity: low
Valid

Unlimited approve to other project contract

Summary

In constructor, contract BridgeSteth call unlimited approve in steth contract for unsteth contract.

Vulnerability Details

Unlimited approve to other contract(other project) is bad practice. Its dangerous. Even famous projects could be hacked.

Impact

If unsteth contract will be hacked, using this approve, tokens could be drained from contrac's balance.

Tools Used

Manual review

Recommendations

Call approve in each call.

Updates

Lead Judging Commences

0xnevi Lead Judge
almost 2 years ago
0xnevi Lead Judge almost 2 years ago
Submission Judgement Published
Validated
Assigned finding tags:

finding-64

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.