Owner-controlled parameters (e.g., liquidationThreshold
) enable protocol abuse.
Parameters like liquidationThreshold
or liquidityBufferRatio
are owner-controlled, allowing governance to arbitrarily alter liquidation logic.
A compromised owner could drain funds or block user interactions (e.g., by setting liquidationThreshold = 0
).
Manual Code Review: Audit parameter-setting functions for access controls.
Use a timelock controller and multisig for parameter updates.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.