MetaEnd🎩 pfp
MetaEnd🎩

@metaend.eth

🚨 Audit Findings on DegenLockToken (Hash: 7c0977a79ef9e48480108f34a3d481f99346cc00) 🚨 πŸ” High Severity: Owner can extend lock duration, impacting all current deposits. This can be used maliciously to lock funds indefinitely. Recommendation: Restrict changes to new deposits or implement decentralized governance. πŸ” Medium Severity: Missing events for critical actions like deposits and withdrawals. Recommendation: Emit events to ensure transparency. πŸ” Informational: Hardcoded token address limits flexibility. Recommendation: Pass the token address as a parameter during contract deployment. πŸ›  Suggested Fixes: Split updateLockDuration function. Implement a killSwitch to set lock duration to 0. Apply updates only to new deposits using a mapping. https://github.com/ngmisl/degenlock-review/blob/main/audit.md
1 reply
0 recast
0 reaction