Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: medium
Valid

Factory address can claim all prize or take a major share of the prize

Summary

Factory address can claim all prize or take a major share of the prize

Vulnerability Details

Msg.sender can set himself as the main/only winner of the contest and can take major share of the rewards.

Impact

An attacker may steal whole or major part of the funds by adding his address in the winner list.

Tools Used

Manual code review
Manual code analysis

Recommendations

CEI should be placed in order of preventing factory address to be in the list of winners.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.