Flow

Sablier
FoundryDeFi
20,000 USDC
View results
Submission Details
Severity: medium
Invalid

adversarial minting of NFT to clog wallet of valid recipient

Summary

A legitimate recipient can have their wallet filled with NFTs that were created with 0 deposits.

Vulnerability Details

Any user can call createto mint Sablier NFTs for only gas fees to the wallet of a recipient, making NFTs impossible to manage.

function _create(
address sender,
address recipient,
UD21x18 ratePerSecond,
IERC20 token,
bool transferable
)

Impact

Management of Sablier NFTs will be difficult, if a user mints streamId of 101 and gets NFTs from 101 - 200.

Tools Used

Manual Review

Recommendations

Permissioned create to reduce the amount of Sablier NFTs minted for free.

Updates

Lead Judging Commences

inallhonesty Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.