All reports
mediumLogic errorEVM-Solidity

AI Arena: Burner role cannot be revoked

Payout
$0
Protocol
AI Arena
Disclosed
May 14, 2024
Source
code4rena

The GameItems contract contains an access control vulnerability where administrative privileges assigned to burner addresses cannot be revoked. The setAllowedBurningAddresses function is designed as an additive-only operation, permanently granting authorizatio …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.