Open hats-bug-reporter[bot] opened 1 year ago
Hello, Thanks a lot for your attention.
This risk is assumed.
It's not in our plan to rug regarding the lawsuit that'd follow after.
Also there is a protection for user on the deposit
function in IBO which is the amountOutMin in CVG token.
We have so to consider this issue as Invalid.
Github username: @goheesheng Submission hash (on-chain): 0x446cb46b124596ec6673fcbed77a2bd521e243ed528d34555d24b30885cfcb7e Severity: high
Description: Description\ The owner is able to falsely inflate prices and crash the protocol.
Attack Scenario\ The hacked wallet is able to create multiple bonds. It can inflate the price and affect the price of the tokens or vice versa. The calculation of the bonds, will thus be affected. Attachments
Proof of Concept (PoC) File
Do create a Role-Based Access Control system if possible.
Without significant redesign, it is not possible to avoid the admin being able to rug-pull the protocol.
As a result, the recommendation is to set all admin functions behind either a timelocked DAO or at least a timelocked multisig contract.