The FjordAuctionFactory contract concentrates significant control in the owner role. The owner can unilaterally change critical addresses and create auctions without any checks or balances.
This centralization could potentially be abused to create malicious auctions or manipulate the system, undermining trust and potentially causing financial losses to users.
The owner can change ownership and create auctions without any additional authorization or time-locks.
Implement a multi-signature wallet or a timelock for sensitive operations.
Consider implementing a governance mechanism for critical decisions.
Add events for all owner actions to increase transparency.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.