Possibility of passing an array of winners which contains an element of address(0), as an argument to distribute function in the implementation contract.
Given the fact that distribute is called through the proxy and the arguments are passed as array of bytes, the ability to pass an array where one or more of the addresses is equal to address(0) and send the rewards of the owner and organizer to the address(0) , the vulnerability is decent.
If that happens there will be big loss of trust in the protocol from all of the users.
Manual
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.