Cross Contract reentrancy
The account state avariable in _claimPlenty
is updated after the transfer, this can lead to reentrancy
users can claim more funds than they deposited . Also be used to steal funds
manual
Use check effect interaction when making transfers
make this code changes
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.