Normal behavior: Administrative privileges should be limited and documented; owner-controlled actions must be intentional and auditable.
Specific issue: the contract exposes multiple onlyOwner functions (mint, burn, refill, pause) granting the owner broad control.
Likelihood:Low
Owner will call admin functions during normal maintenance or upgrades.
Misuse occurs when owner keys are compromised or the owner acts maliciously.
Impact:Low
Owner can change token supply or drain/alter faucet behavior.
Centralization increases trust requirement on the owner.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.