Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: medium
Valid

Lack of Boost Revocation Mechanism in BoostController Contract Enables Irrecoverable Delegations

Summary

The BoostController contract lacks a function that allows a delegator to manually revoke or withdraw a previously delegated boost from a recipient before its expiration. This means that once a boost is delegated, the delegator has no control over reclaiming it, leading to potential misuse or inefficiencies in boost allocation.

Vulnerability Details

A recipient could retain delegated boost even if they become inactive or if the delegator no longer wishes to support them.

Impact

Users cannot dynamically manage their delegated boost, leading to inefficient distribution of boosting power.

Tools Used

Recommendations

Allow the original delegator to manually withdraw their boost before the expiration period.

Updates

Lead Judging Commences

inallhonesty Lead Judge 4 months ago
Submission Judgement Published
Validated
Assigned finding tags:

BoostController: Users unable to remove their own expired boost delegations, creating dependency on recipients and preventing efficient reallocation of boosts

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.