The NFTLiquidator contract contains contract dependencies (crvUSD
, nftContract
, stabilityPool
, and indexToken
) that are not immutable. This introduces a severe risk where an attacker can modify these addresses.
Mutable Critical Contract Addresses, the contract allows the modification of important variables post-deployment:
Potential fund theft, manipulation, or contract exploitation.
Manual review
Change these variables from public to immutable.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.