Flow

Sablier
FoundryDeFi
20,000 USDC
View results
Submission Details
Severity: low
Invalid

Locked Funds Due to Blacklisted Users in Token Streams

Summary

Funds can become permanently locked due to blacklisted users in tokens such as USDC. The current implementation lacks a mechanism to withdraw or reclaim funds from streams involving blacklisted users, leading to a situation where funds may remain inaccessible indefinitely.

Vulnerability Details

The issue occurs when a user involved in the stream becomes blacklisted by the token contract (e.g., USDC).
Due to the absence of a withdrawal or reclamation function for such locked funds, the contract cannot retrieve these assets, resulting in the funds being permanently locked within the contract.

Impact

Funds associated with blacklisted users are irretrievable, remaining indefinitely locked in the contract.

Tools Used

Manual Review

Recommendations

Introduce a function that allows the contract to withdraw or reclaim funds associated with blacklisted users

Updates

Lead Judging Commences

inallhonesty Lead Judge 8 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.