Owner can register malicious ERC20 tokens, leading to fund loss
registerCollateralToken
lacks validation (e.g., checking if the token is whitelisted on Aave V3). A malicious owner could register a fake token, causing deposits to fail or lock funds
Users deposit into unsupported tokens, resulting in irrecoverable funds
Manual review of AaveDIVAWrapper.sol
registration logic
Cross-check tokens against Aave’s official pool addresses
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.