Normal Behavior:
The decentralized_stable_coin.vy contract exports ow.transfer_ownership (line 40), which only transfers the owner role. During deployment, the ERC-20 initialization sets the deployer as both owner and minter.
Specific Issue:
The deployment script (deploy_dsc_engine.py:25) first grants the engine minter permission, then transfers ownership to the engine. Because ow.transfer_ownership does not revoke the old owner's minter role, the original deployer retains unlimited minting power over DSC. The engine contract has no function to revoke this permission either.
Likelihood:
The original deployer can mint unlimited DSC at any time, even after ownership is transferred.
This undermines the entire stablecoin system and can drain collateral from the engine.
No one can revoke the deployer's minter role because the engine has no such function.
Impact:
Impact 1
Impact 2
The test deploys DSC, grants the engine minter permission, and transfers ownership to the engine. After the transfer, dsc.owner() returns the engine, but dsc.is_minter(deployer) still returns True. The test then proves the deployer can mint 1,000,000 DSC out of thin air, even though they are no longer the owner. This confirms the vulnerability.
Fix 1: Export erc20.transfer_ownership instead of ow.transfer_ownership.
Fix 2: provides a manual alternative.
Fix 3: ensures the vulnerability is caught by the test suite.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.