Mystery Box

First Flight #25
Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: medium
Invalid

No Limit on `addReward`

Summary

The addReward function allows the owner to add any number of rewards without restrictions or any checks on the values. This can be abused by a malicious owner to add low-value rewards or flood the pool with useless rewards.

Vulnerability Details

MysteryBox.sol/Line 33

Impact

The contract owner could add numerous low-value rewards, reducing the chances for users to receive higher-value rewards.

Tools Used

Foundry

Recommendations

Add controls or limits on how many rewards can be added or the minimum value of rewards.

Updates

Appeal created

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!