Sparkn

CodeFox Inc.
DeFiFoundryProxy
15,000 USDC
View results
Submission Details
Severity: medium
Valid

A malicious organizer can deceive and withdraw all rewards from sponsors and supporters.

Summary

The organizers are responsible for creating contests and distributing prizes to the winners. However, a dishonest organizer can deceive sponsors and supporters by transferring all rewards once the contest is funded.

Vulnerability Details

After the contest is funded and ended, a malicious organizer can call either the deployProxyAndDistribute() or deployProxyAndDistributeBySignature() function with their controlled addresses to claim all rewards.

Impact

The protocol's reputation could be greatly affected.

Tools Used

None

Recommendations

Since this is related to the design of the entire system, I will leave it to the team.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.