40,000 USDC
View results
Submission Details
Severity: low
Valid

malicious buyer

Summary

buyer could set arbiter address to another valid address owned by him

Vulnerability Details

buyer sets the address, seller calls the getArbiter function to check and see that its a valid address, decides to perform the audit and after delivering the report, buyer decides to call initiate dispute. And call resolveDispute from the arbiter address and sends all the funds back to his buyer address.

Impact

seller doesn't get paid

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.