The CrimeMoney
token doesnt have any access control when transferring the token. So anyone, even non-gangmembers can receive or transfer the token. This is different from what is described in the document: "External users: can only call view functions and deposit USDC."
If a non-gangmember user holds the CrimeMoney token, and refuses to give back, nobody (other than the godfather) can retrieve the USDC back.
add access control in the _update(from, to, value)
function in crimeMoney
:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.