MyCut

First Flight #23
Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: medium
Valid

Funds can remain locked if there are no claimants.

Summary

Funds can remain locked if there are no claimants if Pot contract fixes all of it's existing issues.

Vulnerability Details

The documentation states that when closing pot, manager gets 10 % of the unclaimed rewards and the rest is set to users who claimed. However, there is no logic that handles the case where there are no claimants. This means that funds can remain locked after it fixes the issue that allows for user to claim rewards even after the pot has been closed (claiming after the 90 days period).

Impact

Funds remain locked

Tools Used

Manual Review

Recommendations

If there are no claimants - send the whole prize pool to the manager.

Updates

Lead Judging Commences

equious Lead Judge about 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Incorrect handling of zero claimant edge case

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.