Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: medium
Invalid

Centralization Risk for trusted owners

  • Description:

    • Contracts have owners with privileged rights to perform admin tasks and need to be trusted to not perform malicious updates or drain funds.

  • Impact:

    • Contract owner can change the Streets.sol address to an arbitrary address and cut the mint of the Cred for staked Rappers,

  • Proof of Concept:

    • Access CredToken.sol::setStreetsContract;

    • Input an arbitrary address or even the address(0);

    • Done.

Updates

Lead Judging Commences

inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.