The vulnerability involves a scenario where winners do not receive rewards if any of the winners are blacklisted by a token. The code snippet provided iterates through a list of winners and calculates the amount of rewards they should receive based on percentages. However, it does not appear to account for the possibility that some winners might be blacklisted by the token contract. This means that even if a winner is eligible to receive rewards according to the distribution logic, they might not receive any rewards if they are blacklisted.
Severity: Medium
Impact: HIGH
LikelyHood: Low
The exclusion of legitimate winners from receiving rewards if any of the winners are blacklisted by the token contract, potentially leading to financial losses and compromised fairness.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.