The referrer check to ensure that is not the owner of the position can fooled
When a user creates a trading account, there is the chance to set a referrer. However, there is a check to ensure that the passed referrer is not the caller of the execution.
I assume that this check is made to ensure that the referrer is not the owner of the trading account. However, it can be simply bypassed by creating the trading account with an alt account, set the referrer to the main account and then transfer the position to the main account.
Low
Manual review
I would recommend to erase the referrer when the position is transfered.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.