Insecure randomness that use block timestamp and address as input.
Since the malicious user can manipulate the block.timestamp or use certain msg.sender address value to manipulate the final result.
Hacker can get rarity NFT as much as possible if the value is block.timestamp and block.difficulty is manipulated.
manual review
Use Chainlink VRF to get random number from off-chain method.
Root cause: bad RNG Impact: manipulate winner
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.