On line 47 within openBox() a random number is being generated using the following:
which is an insecure method of generating randomness.
This method of generating randomness is dependent on block.timestamp which can be manipulated by miners. This will essentially allow them to influnece the value of the random number generated.
The impact of this is that miners will be able to consistently target and win a high reward and in essence cheat the system.
Manual Review
Use a trusted source such as Chainlink VRF which allows for provable randomness.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.