There is a potential manipulation of the timeframe by block miners to delay contract owner to close the pot so players have even more time to claim their rewards and also eligible to get additional rewards from the remainder for making their claims on time.
The Pot contract currently using block.timestamp for i_deployedAt which is used in Pot:closePot function to check if the pot is still open for claim process.
If a miner also happens to be in the players list and for some reasons away and needs more time for rewards claim process, the miner could manipulate the block.timestamp of the i_deployedAt so he could have more time buffer apart from the 90 days condition by the owner.
Manipulation of the closePot effective timeframe to gain extra time buffer for reward claim process
Manual review
Protocol team to have proper planning and use a more precise execution timeframe for contract deployment during the creation of the pot and the close of the pot.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.