Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: medium
Valid

The organizer can be a winner - potential token steal

Summary

The organizer address can be added as a winner.

Vulnerability Details

The winner address can be anyone (also the organizer address). The organizer has the power to distribute the prize including also the winner addresses. So the organizer can add his/her address as a solo winner and steal all the funds of the contest.

Impact

In the described vulnerability the steal of the funds is limited to one contest but it could involve a huge amount of money (it depends on how many funds have been collected for the specific contest). Another important aspect to consider is the loss of trust in the protocol. The stealing of money (few or many) leads to a loss of trust with a consequence of loss of users.

Tools Used

Manual

Recommendations

Add an if condition for excluding the organizer address in the distribution function.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.