StrategyArb::setRouter and StrategyOp::setRouter do not reset token approvals.
When the router is updated, token approval is not removed for the old router.
Even after changing the router address to a new one on the strategy, the old router has complete control over strategy's tokens. This can lead to losses in cases of a compromised router.
Manual Review
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.