Attacker can add multiple address to the holders array variable using the increasePosition with 1 wei worth of asset value causing multiple operation that iterate through this array to revert or too expensive to execute to easily break the protocol, rendering the contract non-useable
The increasePosition checks that only a unique address is added to the holders array, however an attacker can still execute this with multiple addresses.
Attacker can add multiple address to the holders array variable using the increasePosition with 1 wei worth of asset value
Multiple operation that iterate through this array will revert or too expensive to execute easily breaking the protocol and rendering the contract non-useable
Manual Review
Add a cap to number of holders
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.