Beginner FriendlyDeFiFoundry
100 EXP
View results
Submission Details
Severity: high
Valid

Unable to claim amount because MerkeAirdrop will have no funds because zkSyncUSD address is wrong

Summary

MerkeAirdrop will have no funds because zkSyncUSD ERC20 address is wrong

Vulnerability Details

MerkeAirdrop does have funds for ERC20 0x1d17CBcF0D6D143135aE902365D2E5e2A16538D4, but in its constructor, it is initialized with 0x1D17CbCf0D6d143135be902365d2e5E2a16538d4 which is the wrong address.

Impact

People will be unable to claim even with a correct proof

Tools Used

Manual

Recommendations

If it's already deployed contract, re deploy with the correct address.
Otherwsie, change the variable value of s_zkSyncUSDC in the deploy script to reflect the correct address on line 18 which is 0x1d17CBcF0D6D143135aE902365D2E5e2A16538D4

Updates

Lead Judging Commences

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

usdc-wrong-address

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.