Scope
src/MultiSigTimelock.sol: Ownable
Normal behavior: Ownable allows single-step transfer.
Issue: If ownership is transferred to an incorrect address (e.g., typo), control is lost permanently.
Likelihood:
Reason 1 // Human error during transfer
Reason 2 // Irreversible action
Impact:
Impact 1 // Permanent loss of admin control
Impact 2 // Inability to manage signers
Explanation: Call transferOwnership with a wrong address. The new owner is set immediately.
Explanation: Use Ownable2Step from OpenZeppelin.
Status: Valid (Best Practice)
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.