Beginner FriendlyFoundryDeFiOracle
100 EXP
View results
Submission Details
Severity: medium
Valid

Owner can rug pull the protocol, centralized

Summary

This protocol is upgradable, means all the functions can be completely changed by an bad owner leading lose of funds to all the liquidity provider.

Vulnerability Details

Even if the owner completely don't rug pull but still this is bad for protocol reputation, and if owner is bad, can change fee of the protocol like if he increase the flashloan fee too high then user will not come for flashloan, hence it will cause funds to sit ideal, not doing anything to gain interests.

Note: Marking this medium because owner needs to be bad.

Impact

LP can lose some funds or in some case completely.

Tools Used

Manual review

Recommendations

Use DAO to approve/change any thing in the protocol.

Updates

Lead Judging Commences

0xnevi Lead Judge
about 2 years ago
0xnevi Lead Judge about 2 years ago
Submission Judgement Published
Invalidated
Reason: Admin Input/call validation
0xnevi Lead Judge about 2 years ago
Submission Judgement Published
Validated
Assigned finding tags:

centralized owners can brick redemptions by unallowing a token

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.