Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: medium
Invalid

Streets contract can be redeployed without users realizing

Summary

Streets contract can be redeployed with malicious code, without users realizing of that. The new contract could point to OneShot and CredToken and Streets variable of both contracts would point to the new malicious Streets contract.

Vulnerability Details

Impact

staking and unstaking logic could be malicious and steal users NFTS without users knowing the change in the logic.

Tools Used

Manual review

Recommendations

Change public variables that contains address of contracts to inmutable, so they are only updated once the contracts are deployed and never again.

Updates

Lead Judging Commences

inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.