Volt Protocol contest - Meta0xNull's results

Inflation Protected Stablecoin.

General Information

Platform: Code4rena

Start Date: 31/03/2022

Pot Size: $75,000 USDC

Total HM: 7

Participants: 42

Period: 7 days

Judge: Jack the Pug

Total Solo HM: 5

Id: 102

League: ETH

Volt Protocol

Findings Distribution

Researcher Performance

Rank: 19/42

Findings: 2

Award: $216.80

🌟 Selected for report: 0

🚀 Solo Findings: 0

Awards

137.8903 USDC - $137.89

Labels

bug
QA (Quality Assurance)

External Links

1) onlyGovernor Call revokeGovernor() Should Take Extra Care

Risk Level: Low

Impact

onlyGovernor is the Super User in this Protocol. onlyGovernor can change all the roles in this protocol. onlyGovernor also responsible to set important parameters. Thus, Revoke Governor Role should take extra care.

Proof of Concept

https://github.com/code-423n4/2022-03-volt/blob/main/contracts/core/Permissions.sol#L114-L116

Suggest revokeGovernor() Add Count Down Time eg. 7 Days as Cooling Down Period to double confirm onlyGovernor want to revoke his Governor role.

#0 - ElliotFriedman

2022-04-05T22:19:33Z

We agree that you have to be careful with the governor and revoking its abilities. Eventually the VOLT system will move to a timelock and token voting mechanism for governance so there will be a time-locked cool down period built in automatically.

Awards

78.9108 USDC - $78.91

Labels

bug
G (Gas Optimization)

External Links

#0 - ElliotFriedman

2022-04-04T17:02:04Z

Agreed that these could be changed to save a bit of gas on the sad path.

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter