QuantAMM

QuantAMM
49,600 OP
View results
Submission Details
Severity: low
Invalid

The `UpdateWeightRunner` contract admin can't be changed

Summary

The UpdateWeightRunner.quantammAdmin is immutable. So in case of the address compromising it can't be changed and the important contract functionality could be controlled by a malicious user.

Vulnerability Details

address public immutable quantammAdmin;

Impact

Unexpected behavior, potential assets losses

Tools used

Manual Review

Recommendations

Consider implementing functionality for the admin address changing.

Updates

Lead Judging Commences

n0kto Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.