52221 sc insight hardcoded supra subscription wallet can freeze spin
Description
Brief / Intro
Vulnerability Details
// immutably set at initialise()
address public admin; // ← subscription wallet
...
uint256 nonce = supraRouter.generateRequest(
callbackSignature,
rngCount,
numConfirmations,
clientSeed,
admin // ← _clientWalletAddress
);Impact Details
Recommendation
Proof of Concept
Previous51391 sc low enabletoken function overwrites amountsold to zero causing permanent loss of sales historyNext52843 sc low the zero address cannot be whitelisted which means during restrictions minting and burning cannot work
Was this helpful?