Unprotected call to a function sending Ether to an arbitrary address.
Unprotected call to a function sent via MockEntryPoint._compensate(address,uint256)
(src/mocks/MockEntryPoint.sol#1138-1142).
The _payPrefund
function could be susceptible to reentrancy attacks.
Slither
Ensure that an arbitrary user cannot withdraw unauthorized funds.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.