40,000 USDC
View results
Submission Details
Severity: gas
Valid

If the arbitor is setup to take respond or get pinged from escrows,he will be spammed

Summary

arbitor can be pinged many times by creating a vault and then setting the state disputed

Vulnerability Details

ex:
StarKing protocol makes 1000 escrows vaults on polygon causing the arbitor to be pinged 1000 times (like discord) on the event for a dispute
The seller does the same thing causing more spamming

Impact

This will cause potentially the arbitor to run out of gas for arbitrating like if it becomes a bot, and it will run out of gas. Also just if they set up some way to collect events for certain arbitor they can be spammed the same thing is for buyers/sellers

Tools Used

Recommendations

Add whitelist feature on backend/sc or fee mechanism when creating a vault

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.