Only addresses with SIGNING_ROLE should influence transaction execution.
If a signer:
Confirms a transaction
Later loses SIGNING_ROLE
Their confirmation remains valid forever, even though they are no longer authorized.
Describe the normal behavior in one or more sentences
Explain the specific issue or problem in one or more sentences
Likelihood:
Occurs when admin removes compromised or malicious signer
Occurs during signer rotation
Impact:
Revoked signers still influence fund movement
Breaks role-based security model
Or enforce onlyRole(SIGNING_ROLE) at execution-time confirmation validation.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.