Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: high
Invalid

Anyone can mint index tokens

Summary

Anyone can call mint on out IndexToken

Vulnerability Details

Anyone can call mint on out IndexToken as it lacks a modifier

function mint(address to, uint256 amount) external {
if (to == address(0)) revert InvalidAddress();
_mint(to, amount);
}

Impact

This token can be used in multiple contracts. For example if used as staking token insage one of the gauged it would allow users to minth themselvs as many staking tokens as they want.
Using this token is dangerous as anyone can mint as much as they want.

Tools Used

Manual review

Recommendations

Add a modifier allowing only the owner/minter to mint.

Updates

Lead Judging Commences

inallhonesty Lead Judge 7 months ago
Submission Judgement Published
Invalidated
Reason: Out of scope

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!