Owner-controlled parameters (e.g., liquidationThreshold) enable protocol abuse.
Parameters like liquidationThreshold or liquidityBufferRatio are owner-controlled, allowing governance to arbitrarily alter liquidation logic.
A compromised owner could drain funds or block user interactions (e.g., by setting liquidationThreshold = 0).
Manual Code Review: Audit parameter-setting functions for access controls.
Use a timelock controller and multisig for parameter updates.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.