Whitelisted users can send tokens to anyone, not only to other whitelisted addresses
TempleGold::_update
check if sender and receiver are authorized, and revert only of both are not, but should revert if at least one of them is not authorized:
Which means if user is authorized, it does not matter how is receiver, it will pass the check
Users can send tokens to not authorized users
Manual review
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.