In the OperatorVault
, the rewards receiver plays a crutial role as it's the only allowed entity to withdraw rewards from the vault
As can be seen rewards are transfered directly to the receiver, however if this account gets compromised, by current logic there is no way the owner to change the address as it allows only the current receiver to do it. The owner can update only if the receiver is not set yet. This missing functionality can result in funds being stolen from the vault.
Manual Review
Allow only the owner to be able to update the receiver address
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.