Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: medium
Invalid

Public state variables in NFTLiquidator.sol

Summary

The NFTLiquidator contract contains contract dependencies (crvUSD, nftContract, stabilityPool, and indexToken) that are not immutable. This introduces a severe risk where an attacker can modify these addresses.

Vulnerability Details

Mutable Critical Contract Addresses, the contract allows the modification of important variables post-deployment:

IERC20 public crvUSD;
IERC721 public nftContract;
address public stabilityPool;
IndexToken public indexToken;

Impact

Potential fund theft, manipulation, or contract exploitation.

Tools Used

Manual review

Recommendations

Change these variables from public to immutable.

Updates

Lead Judging Commences

inallhonesty Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Out of scope

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!