The 4 Mondrian paintings given to users that create an account abstraction wallet is not randomly distributed as it should.
The tokenURI
function returns one of the 4 Mondrian paintings which however is not randomly distributed to the final user. This because the distribution is based on a predictable number which is the tokenId
.
The statement of random distribution of the NFTs is not verified, with a direct impact on the final user that can predict the NFT painting he will receive knowing the tokenId
.
Manual review
Implement a solution with a verifiable source of randomness. (Chainlink VRF)
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.