DittoETH

Ditto
DeFiFoundryOracle
55,000 USDC
View results
Submission Details
Severity: medium
Invalid

Privilege Escalation from Compromised Owner

Summary

Many sensitive operations are not protected from a compromised owner.

Vulnerability Details

Functions like setAssetOracle, createMarket, transferOwnership do not have protections if the owner address is compromised.

A breach of the owner account could allow taking control of markets and settings.

Impact

Attacker could control markets and system configuration if owner account is compromised.

Tools Used

Manual

Recommendations

  • Use a timelock for sensitive owner operations

  • Implement an owner recovery process

Updates

Lead Judging Commences

0xnevi Lead Judge
almost 2 years ago
0xnevi Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.