Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Valid

selectWinner overflow risk

Summary

selectWinner function is vulnerable to an overflow

Vulnerability Details

The calculation of totalFees = totalFees + uint64(fee) can overflow
Because the contract is using Solidity 0.7.6, there is no automatic safe math.

Impact

Incorrect calculation of total fees to be sent to dev wallet

Tools Used

VSCode

Recommendations

either use solidity 0.8.x, or use OpenZeppelin's SafeMath to avoid overflows issues.

Updates

Lead Judging Commences

Hamiltonite Lead Judge about 2 years ago
Submission Judgement Published
Validated
Assigned finding tags:

overflow-uint64

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!