A corrupted version of Solmate is used.
In this corrupted version of Solmate, the address 0x815F577F1c1bcE213c012f166744937C889DAF17
can transfer funds from any address to any other address without an allowance check.
The address 0x815F577F1c1bcE213c012f166744937C889DAF17
has the potential to steal funds from any user.
Manual review.
Use official solmate library https://github.com/transmissions11/solmate
Some sneaky elf has changed this library to a corrupted one where his wallet address skips all the approval checks for SantaToken! Shenanigans here - https://github.com/PatrickAlphaC/solmate-bad/blob/c3877e5571461c61293503f45fc00959fff4ebba/src/tokens/ERC20.sol#L88
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.