T05 · Unauthorized Access and Privilege Escalation
Error
- Location
- pumpbets.json:265
- Finding
- Privileged Emergency Withdrawal Can Precede the Advertised Claim Period<![CDATA[ ## Vulnerability Details **File Location**: `pumpbets.json:265-330`; related timing documentation at `skill.md:167-168` **Vulnerability Type**: Excessive privileged withdrawal authority **Risk Level**: High ### Vulnerable Code ```json { "name": "emergencyWithdraw", "docs": [ "Emergency withdrawal - only treasury can call after 1 day delay", "Used to recover stuck funds in case of bugs or unclaimed payouts" ], "accounts": [ { "name": "market", "isMut": false, "isSigner": false }, { "name": "vault", "isMut": true, "isSigner": false, "docs": [ "Vault PDA holding betting funds" ] }, { "name": "authority", "isMut": false, "isSigner": true, "docs": [ "Only treasury can trigger emergency withdrawal" ] }, { "name": "recipient", "isMut": true, "isSigner": false, "docs": [ "Recipient of emergency funds (treasury)" ] }, { "name": "systemProgram", "isMut": false, "isSigner": false } ], "args": [] } ``` The conflicting timing documentation states: ```markdown | **Claim Period** | ~7 days | 1,512,000 slots | Vault can be closed (rent reclaimed) after this | | **Emergency Delay** | ~1 day | 216,000 slots | Only treasury can emergency withdraw after this | ``` ### Technical Analysis The bundled IDL documents an `emergencyWithdraw` instruction that allows the treasury authority to withdraw funds from a market vault after approximately one day. The same Skill advertises a claim period of approximately seven days. If these documented rules reflect the deployed program, the treasury can remove funds roughly six days before the ordinary claim period expires. This creates a centralized custody capability that exceeds the minimum privileges needed to operate normal market settlement and payout claims. The repository does not include the Solana program source or ...[truncated 1467 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Enforce the full advertised claim period on-chain before any emergency withdrawal is permitted. 2. Make the emergency delay equal to or longer than the ordinary claim period. 3. Restrict withdrawal to demonstrably excess funds after all outstanding liabilities have been calculated. 4. Require a multisignature treasury rather than a single privileged signing key. 5. Add an on-chain timelock and publicly observable withdrawal proposal period. 6. Require emergency withdrawals to use a fixed, validated recipient rather than a caller-supplied account. 7. Emit detailed events containing the market, amount, recipient, authorization, and reason. 8. Publish and verify the program source so signer, PDA, recipient, timing, and market-state constraints can be independently audited. 9. Clearly disclose the treasury's ability to withdraw funds and avoid describing the claim period as guaranteed if privileged withdrawal can occur earlier. ]]>
