Project

One World
NFTDeFi
15,000 USDC
View results
Submission Details
Severity: low
Invalid

Superficial references to ENS for DAO naming does not account for onchain ENS registry.

Summary

The protocol makes several references to ENSaddress and ENSname inMembershipFactory.sol without being enforced on-chain using the ENS Protocol.

Vulnerability Details

The ENS registry is currently not supported on the Polygon blockchain, making inaccurate references to ENS names not tied to an ENS domain.

Impact

Inaccurate references to ENS for DAO names can lead to scams or phishing attempts, which capitalize on the fact that the ENS protocol does not enforce a DAO's name on-chain.

Tools Used

Manual review

Recommendations

Remove references to ENS names and create a name registry, or use an established domain service, such as Unstoppable Domains, that is enabled in Polygon.

Using the ENS registry for naming individual DAOs would require exploration of cross-chain protocols such as Omni Network's chain abstracted applications to register a dao and link it with the corresponding ENS domain.

Updates

Lead Judging Commences

0xbrivan2 Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.