Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: low
Invalid

Inconsistency between the protocol documentation and the code implementation for time-delayed transfer of RAAC ownership in RAACMinter

Summary

There is no implementation for the transfer of RAAC token ownership. It is not in accordance to what the documentation state. The documentation mentions that one of the purpose of the RAACMinter contract is:

Vulnerability Details

There are some variables declared in the contract assumably for the implementation for the time-delayed and secure mechanism to transfer ownership of the RAAC token. TIMELOCK_DURATION and timeLocks but these variables are not being used rather is there is any function to transfer RAAC token. Even in the RAAC token contract, there is no such implementation.

The documentation also states:

  • Implements a 7-day delay mechanism for transferring RAACToken ownership

  • Provides a 24-hour window after the delay period to complete the ownership transfer

Impact

RAAC token ownership cannot be transfered securely.

Tools Used

Manual review.

Recommendations

Add implementation for transfer of RAAC token while utilizing those unused variables.

Updates

Lead Judging Commences

inallhonesty Lead Judge 7 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!