Missing Transaction Cancellation Mechanism
Once a transaction is proposed, there is no way to cancel it even if it becomes malicious, outdated, or if the recipient address is discovered to be compromised. The transaction remains in the system indefinitely and can be executed at any point after the timelock expires if it gets enough confirmations. This is particularly problematic given that only the owner can propose transactions.
Likelihood:
Once a transaction is proposed, there is no way to cancel it even if it becomes malicious, outdated, or if the recipient address is discovered to be compromised. The transaction remains in the system indefinitely and can be executed at any point after the timelock expires if it gets enough confirmations. This is particularly problematic given that only the owner can propose transactions.
Impact:
Malicious or erroneous transactions cannot be stopped once proposed. If signers accidentally confirm a malicious transaction, or if a transaction becomes dangerous due to changed circumstances, there's no way to prevent execution except hoping signers revoke confirmations.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.