QuantAMM

QuantAMM
49,600 OP
View results
Submission Details
Severity: low
Invalid

The `UpdateWeightRunner` contract admin can't be changed

Summary

The UpdateWeightRunner.quantammAdmin is immutable. So in case of the address compromising it can't be changed and the important contract functionality could be controlled by a malicious user.

Vulnerability Details

address public immutable quantammAdmin;

Impact

Unexpected behavior, potential assets losses

Tools used

Manual Review

Recommendations

Consider implementing functionality for the admin address changing.

Updates

Lead Judging Commences

n0kto Lead Judge 7 months ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.