Flow

Sablier
FoundryDeFi
20,000 USDC
View results
Submission Details
Severity: medium
Invalid

adversarial minting of NFT to clog wallet of valid recipient

Summary

A legitimate recipient can have their wallet filled with NFTs that were created with 0 deposits.

Vulnerability Details

Any user can call createto mint Sablier NFTs for only gas fees to the wallet of a recipient, making NFTs impossible to manage.

function _create(
address sender,
address recipient,
UD21x18 ratePerSecond,
IERC20 token,
bool transferable
)

Impact

Management of Sablier NFTs will be difficult, if a user mints streamId of 101 and gets NFTs from 101 - 200.

Tools Used

Manual Review

Recommendations

Permissioned create to reduce the amount of Sablier NFTs minted for free.

Updates

Lead Judging Commences

inallhonesty Lead Judge 8 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.