Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: low
Valid

The deployProxyAndDistributeSignature function is open to replay attacks

Summary

The deployProxyAndDistributeSignature function is open to replay attacks

Vulnerability Details

Based on the comment written above the deployProxyAndDistributeSignature function,
it says using EIP712 verify signature (which is true) and avoid replay attacks (this is not true).

The EIP712 official documentation states that the proposal doesn't include replay protection.
See: https://eips.ethereum.org/EIPS/eip-712

Impact

An attacker could replay signature, deploy a proxy and distribute prizes even after the contest is supposed to be closed on behalf of an organizer.

Tools Used

Manual review

Recommendations

Use nonce or a unique Id for each transaction

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!