KoinArcade
High Risk
Skill-based Web3 arcade
1 Issues Detected
1
Centralization Risks
KoinArcade's vault (0xa57ebcdb0a28007b36c58890b6c498fdbac6a413) is a UUPS-upgradeable proxy controlled by a single EOA (0x68529db5b66b1fc51e24c13627f23ed6108d6f9e). The implementation (KoinArcadeVault at 0x945c166e29b23dbd2ad41722325dfe7706605bb9) contains three direct transfer functions callable by the owner at any time with no timelock or multisig: adminWithdraw(token, to, amount) transfers any supported token to any address; adminWithdrawBatch(token, recipients[], amounts[]) is the batch version; emergencyWithdraw(token, amount) transfers any ERC-20 to msg.sender. All user-deposited game balance tokens are exposed. The owner can also upgrade the implementation contract arbitrarily. Users must fully trust the single EOA operator. It is recommended to use multisig instead of EOA as owner role.
Summary
High Risk
Audit
DappBay Red Alarm
List Time
May, 08, 2026
Chain
BNB Smart Chain