Moonwell

Moonwell
DeFiFoundry
15,000 USDC
View results
Submission Details
Severity: high
Invalid

Centralisation RIsk: Owner Of `MErc20DelegateMadFixer` Can Take All Funds

Summary

steal all funds

Vulnerability Details

steal all funds , owner can choose an address that is incorrect

Impact

loss of funds

Tools Used

manual

Recommendations

sweep must be set automatically were the funds come from and not an address that the owner chooses.
add a function to validate the sweep address before the transfer is made

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Known issue

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.