burn()
function in contracts/MOR.sol is
not restricted enough. As a consequence, an attacker could use external
methods, such as phishing, to fool legitimate users to burn their own
MOR tokens.
Lost of reward tokens
Manual Review
Restricting the ability of burning MOR tokens to the owner of the contract or to an appropriate authority, e.g: MOR-staking contract
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.