A critical design vulnerability exists in the MembershipFactory's joinDAO function due to the absence of per-address membership limits. This enables users with sufficient capital to purchase all available memberships in crucial tiers, leading to centralized control of what should be a decentralized autonomous organization. The impact is severe as single users can accumulate overwhelming voting power, manipulate profit distributions, and effectively lock out other potential members from meaningful participation.
Single address can own majority voting weight
Controls treasury fund usage
Dictates membership decisions
Manipulates profit sharing
Prevents fair entry
Manual Review
Implement strict per-user limits with upgrade consideration
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.