One-step ownership transfer in setTeam
The setTeam function transferred privileged ownership in a single step with no confirmation from the new owner, creating risk of permanent loss of control if a typo, wrong address, or compromised key is used.
Description
The setTeam function transferred the protocol's "team" privilege to a new address in one step, without requiring the new address to claim or confirm the transfer. A single typo or compromised key during the transfer call would permanently transfer control to an unintended address.
Impact
Permanent loss of administrative control if the wrong address is used. No recovery path without re-deploying or relying on other privileged escape hatches.
Recommendation
Implement a two-step ownership transfer pattern (similar to OpenZeppelin's Ownable2Step) where the new address must explicitly accept the role before the transfer completes.
Composable Security ID: NRL-6c19a5e-L01. Neverland Money: Fixed. Composable Security: Fix verified during retest.