EXTRA_NICE users can call buyPresent
function and trade their SANTA token for a second NFT.
buyPresent
function is set to external and there is no check for the status of the user calling the function. Therefore, an EXTRA_NICE user that has already claimed the present through collectPresent
function can call the buyPresent
function and trade its santa token for a second NFT.
EXTRA_NICE users can trade all of their Santa token for and NFT.
Manual review
add an if statement and revert if user is not NAUGHTY
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.