Blacklisted usdc adress can dos the transfer of tokens for other users.
USDC addresses can be blacklisted, this means that these addresses cannot send or receive USDC. If a winner of a contest were to send the organizer a blacklisted USDC address, when awards are being sent, the for loop will be DOSed when attempting to send USDC to the blacklisted user's address/address he provided to the organizer. The user can be malicious and give the organizer an address he knows is blacklisted, if he himself does not own a blacklisted address.
The transfer of awards will be DOSed/ funds will be stuck.
manual review
implement logic or include a simulation functions that simulates the transfer and ensure there are no blacklisted addresses in the winners[]
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.