Description:
Contracts have owners with privileged rights to perform admin tasks and need to be trusted to not perform malicious updates or drain funds.
Impact:
Contract owner can change the Streets.sol
address to an arbitrary address and cut the mint of the Cred for staked Rappers,
Proof of Concept:
Access CredToken.sol::setStreetsContract
;
Input an arbitrary address or even the address(0);
Done.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.