The modified implementation of ERC20 used in the protocol allows the elves to steal user tokens at any time without requiring approval.
For some reason, the elves have altered the ERC20 implementation, granting themselves excessive power within the protocol.
Users can be deprived of their gifts.
Foundry
Deal with the vulnerabilities introduced by the elves by reverting the ERC20 implementation to its standard form. Consider disciplinary actions for the elves involved.
Some sneaky elf has changed this library to a corrupted one where his wallet address skips all the approval checks for SantaToken! Shenanigans here - https://github.com/PatrickAlphaC/solmate-bad/blob/c3877e5571461c61293503f45fc00959fff4ebba/src/tokens/ERC20.sol#L88
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.