The Standard

The Standard
DeFiHardhat
20,000 USDC
View results
Submission Details
Severity: low
Invalid

Smart Vault Owner's Potential Loss of Access

Summary

Vulnerability Details

The current implementation of SmartVault3#setOwner allows the vaultManager to change the new owner of the vault at any time, even if the vault owners have paid back their debt, and their vault remains healthy. Although it was mentioned that the admin is trusted, it's advisable to impose certain limitations.

Impact

Vault owners can loose access to their vaults at any moment.

Tools Used

Manual

Recommendations

Consider adding a function to setOwner that allows only the vaultManager to change the owner only when the vault is liquidated or undercollateralized.

Updates

Lead Judging Commences

hrishibhat Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Known issue
Assigned finding tags:

informational/invalid

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.