Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: high
Invalid

Voters can be bribed

Summary

Voters can be bribed to vote for the proposal as total rewards can be increased by anyone.

Vulnerability Details

The comment stating that there is intentionally by design no way to decrease or increase this amount is not followed in the code.
Any findings related to not being able to increase/decrease the total reward amount are invalid
Here the total rewards can be increased.
The total rewards use the balance of the contract. Anyone can send ETH to the contract through a selfdestruct and influence the vote.

Impact

Voters can be bribed.

Tools Used

Manual review

Recommendations

Do not rely on the address(this).balance for the total rewards.

Updates

Lead Judging Commences

0xnevi Lead Judge
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.