The contract inherits from Ownable which centralizes critical functionality to a single owner address. The owner has exclusive control over proposing transactions and managing signers.
If the owner's private key is compromised or lost, the entire multisig becomes inoperable. The owner can unilaterally add/remove signers and propose transactions without any checks, creating a centralized point of failure that defeats the purpose of a multisig wallet.
Likelihood:
The owner's private key could be compromised through phishing, malware, or other attacks at any time
Loss of the owner's private key renders the contract permanently inoperable since no other address can propose transactions or manage signers
Impact:
Complete loss of control over the multisig wallet if owner key is compromised
All funds locked permanently if owner key is lost (no recovery mechanism)
Owner can collude with 2 other signers to drain funds without proper oversight
Defeats the decentralization principle of a multisig wallet
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.