A malicious user could participate in the claiming of airstreams on different chains.
A user that has a valid merkle proof could claim the same streams created by a sender on different chains simultaneously and this is due to the lack of chainId
specification in the leaf hash.
If a stream sender decides to create a stream on multiple chains and proceed to fund the stream on multiple chains, a malicious user that has claimed their streams can also claim streams on all other chains in which the stream was deployed.
Claiming of the same stream on multiple chains as the Protocol intends on deploying on all networks.
Manual Review
Add the chainId
to the leaf hash so a user can just claim on a particular chain and not game the entire system.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.