VRC-20 Approve Manager Address
This function sets the Comet contractβs VRC-20 allowance of an asset for a manager address. It can only be called by the Governor.
In the event of a governance attack, an attacker could create a proposal that leverages this function to give themselves permissions to freely transfer all VRC-20 tokens out of the Comet contract.
Hypothetically, the attacker would need to either acquire supreme voting weight or add a malicious step in an otherwise innocuous and popular proposal and the community would fail to detect before approving.
Last updated