code-423n4 / 2021-10-union-findings

0 stars 0 forks source link

Admin has too much power #108

Closed code423n4 closed 3 years ago

code423n4 commented 3 years ago

Handle

pants

Vulnerability details

Admin is capable to deleteMarket without any announcement. We suggest to add a time period in which users allowed to act according to the admin decisions, to make the protocol more decentralized.

GeraldHost commented 3 years ago

The admin is is the governor contract.

GalloDaSballo commented 3 years ago

Agreed in principle with the warden

However the sponsor plans to use the governor contract, mitigation seems sufficient although devil is in the details