As there is missing address(0) check for immutable variables at Fees.sol
’s constructor, malicious actor can set WETH to address(0)
and makes sellProfits
unusable.
Causes undermining the profit distribution mechanism and disrupts intended functionality of the contract.
Manual Code Review
Add zero-address checks
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.