WhisperX tag archive

#admin_privilege

This page collects WhisperX intelligence signals tagged #admin_privilege. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-25 10:27:21 · GitHub Issues

1. Arena Smart Contract Vulnerability: Admin Can Switch Reward Token Mid-Game, Risking User Funds

A critical security flaw has been identified in the Arena smart contract's administrative `set_token` function. The vulnerability allows a contract admin to instantly change the address of the reward or stake token at any time, without regard for the current state of active games. This creates a direct risk where playe...

The Lab · 2026-03-28 11:27:04 · GitHub Issues

2. Arena Game Contract Vulnerability: Admin `set_token` Function Can Permanently Trap Player Funds

A critical security vulnerability has been identified in the Arena game contract, where an administrative function can permanently lock player deposits mid-game. The `set_token` function, which mutates the underlying `TOKEN_KEY` for the prize pool, lacks essential lifecycle guards. This allows an admin—whether acting a...