This codebase is not very well documented. The readme is good, but no natspec and descriptions of the inner workings makes this harder to read. Maybe tht is the point.
Security through obscurity is not really a thing, its just an annoyance.
Admittedly it makes this harder to decipher, which may be the point, but along with the other issues, this points to a general lack of engineering sophistication within this project.
Put in comments which describe the core functions and interactions of the protocol. The GodFather is going to have to get dirty with this codebase if they are going to have any chance of salvaging anything, and I am sure they would appreciate some better signposts.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.