An attacker could manipulate the game outcome by strategically filling a large number of player slots.
The contract allows up to 30 players.
Ivan and his 15 friends are guaranteed slots, leaving 14 open slots.
An attacker could:
Register 14 addresses (filling all remaining slots)
Use each addresses to bet on First, Draw, and Second outcomes
Game manipulation: The attacker is guaranteed to have multiple correct predictions for each match, regardless of the outcome.
Reward domination: The attacker's addresses would likely accumulate a significant portion of the total positive points, leading to a larger share of the rewards.
Manual code review
Implement KYC for non-trusted players.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.