Highlights
Access Control: 29 prior fixes. Scrutinize any change in this area.
contracts/RocketDepositToken.sol: most-fixed (5 issues). Treat as high-risk during review.
34 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Access Control: Multiple fixes address missing or incorrect caller authorization on fund-distribution and withdrawal functions, allowing unauthorized parties to trigger transfers or hijack withdrawal addresses.
Access Control: Validator lifecycle functions (notifyExit, stake, dissolve, newValidator) lacked proper state and bond checks, enabling unauthorized exits or underbonded validator creation.
Auth Bypass: Authorization checks on staking permission and withdrawal address management were missing or easily bypassed, allowing unauthorized staking or address hijacking.