First Flight #20: The Predicter

Beginner FriendlyFoundry
100 EXP
Submission Details
Severity: high
Valid

Reentracy Attack in `ThePredicter::cancelRegistration`, this function did not update `playersStatus[msg.sender]` before transfer `entranceFee` back to user, malicious user can steal all money from contract

Updates

Lead Judging Commences

NightHawK Lead Judge 3 months ago
Submission Judgement Published
Validated
Assigned finding tags:

Reentrancy in cancelRegistration

Reentrancy of ThePredicter::cancelRegistration allows a maliciour user to drain all funds.

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.