Beginner FriendlyDeFiFoundry
100 EXP
View results
Submission Details
Severity: high
Valid

Recipient can steal other's airdrop.

Summary

Single recipient can claim all the airdrop by calling claim multiple times.

Vulnerability Details

claim function can be called multiple times by the recipient ,which will give him all the available USDC that was meant to be for others.

Impact

user can steal all the airdrop.

Tools Used

Manual review

Recommendations

Record the address of the user who have already claimed the airdrop and do not allow him if he calls the claim function again.

Updates

Lead Judging Commences

inallhonesty Lead Judge
over 1 year ago
inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

multi-claim-airdrop

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.