There are setRouter
in StrategyArb
and StrategyOp
, which allows admins to update router address, however, approval for previous router is not revoked.
Upon update, new router will be granted with max approval:
But we can notice, the approval of previous router is not revoked, this mean previous router still has max allowance on the strategy, while the routers themselves will not pose any threats to the protocol, it's still not a good practice to do so.
Router approval presists, in extreme edge case, if router is set to a malicious one, then such router can drain the strategy.
Manual review
When setting new router, also revoke previous approvals.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.