TempleGold

TempleDAO
Foundry
25,000 USDC
View results
Submission Details
Severity: medium
Invalid

An account can delegate votes to more than one address.

Summary

An account can stake alot of tokens . then delegate to different address thus manipulating the strength of address from the same staked tokens.

Vulnerability Details

  1. bob stakes alot of tokens

  2. calls delegate and gives the power to alice

  3. bob calls again delegate to ken

  4. so new delegator becomes ken and receives same power as alice.

  5. so ken and alice have same power from the same delegator.

There was no update to alice by removing the votes from so this method can be used to share power to more than one account.

Impact

Manipulation by delegating different addresses thus sharing power.

Tools Used

manual

Recommendations

when there is change in delegation. update old delegator to remove the vote from old to new delegator.

Updates

Lead Judging Commences

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.