The strategy contract grants maximum token approval to the transmuter and router to facilitate seamless interactions. However, if either the transmuter or router is compromised, an attacker could exploit the unlimited approval to drain tokens from the strategy contract.
The strategy contract simplifies interactions by granting unlimited token approval to the transmuter and router:
If the transmuter or router contracts are exploited, an attacker can transfer or drain all approved tokens from the strategy contract, potentially resulting in the loss of all user-deposited funds managed by the strategy.
All tokens in the strategy contract could be drained by an attacker exploiting the transmuter or router.
Manual Review
Avoid granting unlimited token approval. Instead, approve only the required amount for each transaction.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.