Random number generator (RNG) is not truly random and miners can interfere with the winner selection.
Since on-chain data is used (such as block.timestamp
and block.difficulty
), theoretically, miners could interfere and possibly select themselves as winners, due to their access to protocol-level variables, such as block
.
High risk, low likelyhood
Manual inspection.
Use verifiably and truly random numbers, such as RANDAO or Chainlink's VRF, to select winners.
Root cause: bad RNG Impact: manipulate winner
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.