In the event AaveDivaWrapper
contract is compromised, there is no mechanism to transfer ownership of WToken
.
Throughout the protocol, WToken
plays an important role in being used as the collateral in DIVA protocol.
The authorizations to mint and burn WTokens
are given to the AAVEDivaWrapper contract. However, in the scenario where the ownership needs to be transferred (e.g. if AaveDIVAWrapper contract is compromised), ownership of WTokens cannot be transferred.
AaveDIVAWrapper cannot transfer ownership of WToken to a trusted address which impacts the integrity of the protocol.
Consider implementing logic to allow ownership of WToken
to be transferred
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.