Only four token are allowed to sell
setAllowedSellToken doesn't restrict which token to sell.
Likelihood:
Reason 1 Human error(owner might add malicious tokens)
Reason 2 Attacker become owner (private key leak)
Impact:
The onlyOwner
role can whitelist any ERC20 token (except address(0)
/USDC
).
Malicious token can leads to loss of funds.
Attacker steals funds or causes trade to fail.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.