Mystery Box

First Flight #25
Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: medium
Invalid

[EVMN] No Check To Valudate `_to`

Summary

There is no check on address _to which could lead to unclaimable reward.

Vulnerability Details

The code on line 75 below pushes a reward that belongs to msg.sender to _to.

rewardsOwned[_to].push(rewardsOwned[msg.sender][_index]);

However, there is no check whether _to is a valid address. If _to is a zero address, then the reward is unclaimable.

Impact

A reward can become unclaimable.

Tools Used

Manual review.

Recommendations

Consider adding a check to prevent a zero address on _to.

Updates

Appeal created

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!