admin-functions

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A missing access control and unchecked state transition vulnerability in Alchemist's TimelockConfig.confirmChange() function allows attackers to call confirmChange() without authorization and set arbitrary config parameters to 0, including bricking the admin wallet and mint recipient, which permanently halts token inflation distribution to stakers. The root cause is Solidity's behavior of returning default zero values for non-existent map entries rather than reverting.

Alchemist Fjord Foundry TimelockConfig Aludel Crucible StreamV2 MIST token
dacian.me · Dacian · 17 hours ago · details