No check in the stake function.
There is no check in the stake function to ensure that any user calling the function and passing in a tokenId(to be staked), is actually the owner of this tokenId. As a result, a tokenId owned by one user can be staked by another user who doesn’t own it.
A user’s token can be staked by anybody.
Manual Inspection
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.