Either by mistake or malicious action, admin can rug stakers by sending out reward tokens via recoverTokens function
The recoverTokens function is designed to be used by admin to recover tokens accidentally sent to the contract.
While the admin account is trusted, this setup does not inspire confidence in customers, especially those who have been rugged in other protocols. No caution is in place to remove chance of loss of stakers.
Protocol customers are likely to view the project with suspicion in terms of asset safety.
Manual review
Ensure that the tokens to sent out are not among the reward tokens.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.