If a participant in staking is a multisig wallet and tries to claim rewards, a mint message would be sent to Arbutrim chain with the address of the multisig wallet. However multisigs are contracts deployed on chains and that's why destination chain address, which corresponds to source chain address won't be owned by the same person/s
In common case rewards would be sent to some random user who may don't want to refund them.
In the worst case expoiter can deploy contract on the following address and claim MOR tokens.
See Wintermute
Lost rewards for participants, who use multisig wallets. This is more ofter practice. Also the problem could occur in other account abstraction scenarios.
Manual Review
Make claim
function callable only by the owner and let him pass receiver
address for the destination chain:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.