Tadle

Tadle
DeFiFoundry
27,750 USDC
View results
Submission Details
Severity: low
Invalid

single step ownership transfer used instead of 2 Step Transfer

Summary

Vulnerability Details

The protocol uses Ownable from OpenZeppelin which is not ideal for protocols where it can leave the contract without owner if they transfer the ownership to a wrong address.

Single Step ownership transfer is dangerous as if the transfer is made to an incorrect address, the contract will be with no owner, and the role will be lost forever.

Impact

All onlyOwner() functions will not be callable by the Tadle team

Tools Used

Manual review

Recommendations

Use OZ::Ownable2StepUpgradeable.sol instead of single step ownership transfer.

Updates

Lead Judging Commences

0xnevi Lead Judge
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Known issue

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!