The claim
function of MerkleAirdrop.sol
is lacking a mechanism, which would mark an airdrop as claimed. This enables an airdrop winner to drain the whole protocol by repeatedly calling the claim
function.
High, as a claimer can repeat the claim multiple times, until draining the whole contract.
Manual Review
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.