ERC20:transferFrom#L89
allows particular address to transfer tokens from any address.
The South Pole Elves hardcoded address of particular address that can is allowed to transfer any amount of tokens from any account, thus stealing the tokens from any user.
High, privileged account can steal tokens from users.
Manual Review.
Remove malicious code.
Some sneaky elf has changed this library to a corrupted one where his wallet address skips all the approval checks for SantaToken! Shenanigans here - https://github.com/PatrickAlphaC/solmate-bad/blob/c3877e5571461c61293503f45fc00959fff4ebba/src/tokens/ERC20.sol#L88
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.