criticalLogic errorEVM-Solidity
Fenix Finance: Single-step process for critical ownership transfer is very risky
- Payout
- $0
- Protocol
- Fenix Finance
- Disclosed
- Feb 28, 2024
- Source
- hats
Fenix Finance's BribeFactoryUpgradeable inherits OpenZeppelin's single-step OwnableUpgradeable, so a one-call transferOwnership to a mistyped address permanently hands ownership to an address whose private key is unknown. Every onlyOwner-protected function — i …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Fenix-Finance-0x83dbe5aa378f3ce160ed084daf85f621289fb92f/issues/40
- https://github.com/hats-finance/Fenix-Finance-0x83dbe5aa378f3ce160ed084daf85f621289fb92f
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.