Beginner FriendlyFoundryDeFiOracle
100 EXP
View results
Submission Details
Severity: medium
Valid

Deleting the token mappings may result of locking the funds permenantly in assetToken contract

Vulnerability Details

Deleting the value in mapping may result in the Tokens lock in the assetToken permenantly and can't be backed by anymore.In the setAllowedToken() owner can unassign the tokens at any time if the owner unassigns the token then the ThunderLoan contract can't be able to interact with the assetToken contract result in tokens lock and there is no withdraw function or anything in the assetToken contract to get back the tokens.

Impact

High

Tools Used

Manual Review

Recommendations

Add withdraw function in the assetoken conctract.

Updates

Lead Judging Commences

0xnevi Lead Judge
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Admin Input/call validation
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

centralized owners can brick redemptions by unallowing a token

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.