HardhatDeFi
15,000 USDC
View results
Submission Details
Severity: medium
Invalid

Unrestricted Collateral Token Registration

Summary

Owner can register malicious ERC20 tokens, leading to fund loss

Vulnerability Details

registerCollateralToken lacks validation (e.g., checking if the token is whitelisted on Aave V3). A malicious owner could register a fake token, causing deposits to fail or lock funds

Impact

Users deposit into unsupported tokens, resulting in irrecoverable funds

Tools Used

Manual review of AaveDIVAWrapper.sol registration logic

Recommendations

Cross-check tokens against Aave’s official pool addresses

Updates

Lead Judging Commences

bube Lead Judge 5 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.