Approve function can be front run
Approve can be front run and used as phishing attack vector just like tx-origin--> with different airdrop list.With block stuffing attack to forcing the real transaction revert so create phishing attack chance in case needed.
Airdrop can be stolen by phishing scam just as using tx.origin method.
Manuel review
Create deposit functionality to remove this threat
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.