Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: high

You can start a contest with not a whitelisted token

Summary

You can start a contest with not a whitelisted token

Vulnerability Details

There is not check if the token for the contest is whitelisted, except in the Distrubete.sol _distrubete().
After the contest is finished the auditors cannot withdraw their winning prize because only then there is check for whitelisted token.

Impact

Loss of funds

Tools Used

manual Review

Recommendations

check if the prize is whitelisted token in ProxyFactory.sol setContest()

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!