The contract relies on external signatures through rankCandidatesBySig
, but there is no nonce or time-based mechanism to prevent replay attacks. Mitigation: Implement a nonce system or timestamp check to prevent the reuse of a valid signature.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.