sherlock-audit / 2024-02-telcoin-platform-audit-update-judging

3 stars 1 forks source link

DiGarOn - Excessive centralization Medium #32

Closed sherlock-admin2 closed 8 months ago

sherlock-admin2 commented 8 months ago

DiGarOn

medium

Excessive centralization Medium

Summary

Some roles have too much power.

Vulnerability Detail

Impact

Medium. Such centralization can lead to loss of confidence in the project. also, in case of a key leak of one of the previously mentioned roles will lead to loss of money from the whole project.

Code Snippet

https://github.com/sherlock-audit/2024-02-telcoin-platform-audit-update/blob/21920190e0772afa18e7f856a036fea3ef5b9635/telcoin-contracts/contracts/util/abstract/Blacklist.sol#L72 https://github.com/sherlock-audit/2024-02-telcoin-platform-audit-update/blob/21920190e0772afa18e7f856a036fea3ef5b9635/telcoin-contracts/contracts/factories/ProxyFactory.sol#L85C59-L85C71 https://github.com/sherlock-audit/2024-02-telcoin-platform-audit-update/blob/21920190e0772afa18e7f856a036fea3ef5b9635/telcoin-contracts/contracts/stablecoin/Stablecoin.sol#L74C50-L74C61 https://github.com/sherlock-audit/2024-02-telcoin-platform-audit-update/blob/21920190e0772afa18e7f856a036fea3ef5b9635/telcoin-contracts/contracts/stablecoin/Stablecoin.sol#L106 https://github.com/sherlock-audit/2024-02-telcoin-platform-audit-update/blob/21920190e0772afa18e7f856a036fea3ef5b9635/telcoin-contracts/contracts/swap/AmirX.sol#L234

Tool used

Noen

Manual Review

Recommendation

Refuse such centralization. Switch to a government system and do not take money from users for nothing.

sherlock-admin2 commented 8 months ago

1 comment(s) were left on this issue during the judging contest.

WangAudit commented:

centralization risks are not valid