Assessment reports>Rainmaker>Discussion>Underlying vault requires verification

Underlying vault requires verification

The security and trust model of a given staking manager is heavily dependent on the underlying Definitive vault. It is the responsibility of users to verify that a staking manager's definitiveVault

  1. is indeed one of the strategies deployed by Definitive and

  2. is properly configured.

In particular, there should be no other accounts except for the staking manager with ROLE_CLIENT on the underlying definitiveVault. Otherwise, those accounts may have the ability to steal user funds. We encourage Rainmaker to provide thorough documentation for users.

Zellic © 2024Back to top ↑