The protocol allows the owner to instantly change price feed addresses for any token. An honest owner ensures correct Chainlink feeds are used, but a malicious or compromised owner can replace legitimate feeds with malicious contracts that return manipulated prices, enabling theft of all user funds with no warning.
Likelihood:
Owner key compromise happens regularly in DeFi (hot wallet exploits)
Malicious insider with owner access
Owner decides to rug users
Impact:
Owner sets malicious price feed returning fake prices
Opens positions at fake favorable prices, stealing protocol funds
Liquidates all user positions by manipulating prices
Complete loss of all deposited collateral
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.