Project

One World
NFTDeFi
15,000 USDC
View results
Submission Details
Severity: medium
Invalid

No way to change owpWallet in MembershipFactory contract.

Summary

The owpWallet receives fee tokens when users joins a Dao.

Vulnerability Details

The MembershipFactory contract does not provide a mechanism to update the owpWallet address. As a result, if the owpWallet is ever compromised, the protocol's functionality will be severely affected. Since the MembershipFactory contract is also not upgradeable, the protocol owners will not have the ability to modify the owpWallet address. Consequently, any user fees will continue to be directed to the compromised wallet, putting user funds at risk.

Impact

The inability to update the compromised owpWallet address results in a continuous loss of user funds and potentially disrupts the entire protocol’s operation.

Tools Used

Manual

Recommendations

Add an mechanism to change owpWallet.

Updates

Lead Judging Commences

0xbrivan2 Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Design choice
0xbrivan2 Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!