Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Valid

Reliance on block.timestamp in selectWinner could result in the raffle being manipulated

Summary

Reliance on block.timestamp could result in the raffle being manipulated

Vulnerability Details

The use of block.timestamp to determine when a winner can be selected is problematic in that block values can potentially be manipulated by a miner to their advantage.

Impact

Low

Tools Used

VS Code
Slither

Recommendations

Use an external source to obtain the current time

Updates

Lead Judging Commences

Hamiltonite Lead Judge almost 2 years ago
Submission Judgement Published
Validated
Assigned finding tags:

weak-randomness

Root cause: bad RNG Impact: manipulate winner

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.