Everyone who run test will be pwned
testPwned
function in test/unit/SantasListTest.t.sol
inserts malicious file
private key lose, fund lose, harm users...
* Note: I am not sure how to do a PoC of this one. As it's not in a scope I am not sure is it a finding. But certainly is very harmful
Manually
Remove testPwned
function from SantasListTest.t.sol
before running tests
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.