Snow::changeCollector
Function.The Snow::changeCollector
Function can only be called by current collector.since the
collector role can claim the protocol fees of users which can lead to potential high
vulnerability if the current collector becomes malicious or compromised.
Impact:
1.Current collector can change the collector to an unauthorised or malicious address.
2.Can redirect fees to themselves or to any other unintented address.
Attack Scenario:
Current Collector can update the address of collector via changeCollector
function to malicious address.
Protcol's critical function must be called by Owner Only.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
View preliminary resultsAppeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.