Access control flaws allow unauthorized users to perform privileged operations. Learn how to implement proper authorization and protect your smart contracts.
onlyOwner modifier on an admin function.Ownable or AccessControl, apply onlyOwner to every admin function, require multisig for high-value privileged operations.Access control flaws occur when smart contracts fail to properly restrict access to sensitive functions. This can allow unauthorized users to perform privileged operations like withdrawing funds, changing critical parameters, or taking control of the contract.
Single owner has complete control over contract functions. Simple but centralized.
Multiple roles with specific permissions. More flexible and secure than owner-only.
Requires multiple signatures for critical operations. Reduces single point of failure.
Access rights that change over time or have expiration dates.
Access control flaws are vulnerabilities where smart contract functions that should be restricted — like minting tokens, pausing a protocol, or upgrading a proxy — can be called by anyone. The most common cause is a missing `onlyOwner` or role modifier on admin functions.
Access control is the #1 cause of DeFi losses by dollar amount. The HospoWise hack ($3.5M, 2021), the Uranium Finance exploit ($50M, 2021), the Ronin Bridge breach ($625M, 2022), and the WEMIX exploit ($6.25M, July 2026) all involved unauthorized callers executing privileged functions. Many were single missing `onlyOwner` checks.
Forgetting to apply a modifier to sensitive functions — especially initialize() in upgradeable contracts, which is often left unprotected. A public initializer without an access guard lets any attacker reinitialize a proxy and take ownership. OpenZeppelin's Initializable helps, but only if used correctly.
RBAC assigns different permission levels to different addresses using a role registry. OpenZeppelin's AccessControl contract is the standard implementation — it lets you define roles like MINTER_ROLE, PAUSER_ROLE, and ADMIN_ROLE and grant them independently, reducing the blast radius of a compromised key.
Yes — access control review is a core part of every professional smart contract audit. SmartContractAuditor.ai automatically maps all state-changing functions, checks which have access modifiers, flags missing guards on privileged operations, and highlights initialize() exposure in upgradeable contracts.