Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: medium
Invalid

Direct Tokens Transfers Will Be Stuck

Summary

Tokens sent directly to the Treasury contract (i.e., not via the designated deposit function) will be permanently locked, resulting in stuck funds.

Vulnerability Details

The Treasury contract uses internal accounting for its token balance, which is updated only through the deposit and withdraw functions. If tokens are transferred directly to the contract—bypassing these functions—the contract will not recognize or account for them. Consequently, these tokens become stuck with no mechanism for recovery.

Impact

  • Permanent Loss of Funds: Tokens transferred directly to the Treasury contract will be irretrievable. Low likelihood high impact.

Tools Used

  • Manual Review

Recommendations

Add an emergency withdrawal or token recovery function to allow the retrieval of tokens that are accidentally sent directly to the contract.

Updates

Lead Judging Commences

inallhonesty Lead Judge about 2 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
inallhonesty Lead Judge about 2 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.