The signature used in ProxyFactory::deployProxyAndDistributeBySignature()
is missing a nonce & expiration deadline.
The signature used in ProxyFactory::deployProxyAndDistributeBySignature()
is missing a nonce & expiration deadline.
This doesn't appear to currently be directly exploitable as ProxyFactory::_distribute()
can't be called using the signature but without attempting to deploy the proxy. However the project team has stated they will be upgrading the contracts and that the current code is just an initial version, so best to point this out now as a low finding to prevent it from becoming a medium/high in a future version of the codebase.
Manual
Implement a nonce and an expiration deadline.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.