Funds can become permanently locked due to blacklisted users in tokens such as USDC. The current implementation lacks a mechanism to withdraw or reclaim funds from streams involving blacklisted users, leading to a situation where funds may remain inaccessible indefinitely.
The issue occurs when a user involved in the stream becomes blacklisted by the token contract (e.g., USDC).
Due to the absence of a withdrawal or reclamation function for such locked funds, the contract cannot retrieve these assets, resulting in the funds being permanently locked within the contract.
Funds associated with blacklisted users are irretrievable, remaining indefinitely locked in the contract.
Manual Review
Introduce a function that allows the contract to withdraw or reclaim funds associated with blacklisted users
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.