The SmartVaultManager has an owner with privileged rights to change vault's owner, then can steal all vault's funds.
The SmartVaultManager has an owner with privileged rights to change vault's owner.
The SmartVaultManager contract is a upgradeable contract. The owner of the SmartVaultManager contract can easily upgrade the SmartVaultManager contract added a function like below:
So the owner of the SmartVaultManager contract can easily change all vault's owner address to his's owner address, then steal all funds.
Centralization Risk for that the owner of the SmartVaultManager contract can easily change all vault's owner address to his's owner address, then steal all funds.
Foundry
The owner of vault should not be changed by the SmartVaultManager.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.