The owpWallet receives fee tokens when users joins a Dao.
The MembershipFactory contract does not provide a mechanism to update the owpWallet address. As a result, if the owpWallet is ever compromised, the protocol's functionality will be severely affected. Since the MembershipFactory contract is also not upgradeable, the protocol owners will not have the ability to modify the owpWallet address. Consequently, any user fees will continue to be directed to the compromised wallet, putting user funds at risk.
The inability to update the compromised owpWallet address results in a continuous loss of user funds and potentially disrupts the entire protocol’s operation.
Manual
Add an mechanism to change owpWallet.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.