Starknet Auction

First Flight #26

Starknet Auction

Beginner FriendlyNFT
100 EXP
View results
Submission Details
Severity: high
Valid

Re-entrancy Attack on Withdraw Function

Updates

Lead Judging Commences

bube Lead Judge 3 months ago
Submission Judgement Published
Validated
Assigned finding tags:

Reentrancy in `withdraw` function

The `withdraw` function doesn't reset the `bid_values` to 0 after the withdraw. That means the bidder can call multiple time the `withdraw` function and receive the whole balance of the protocol.

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.

Cyfrin
Updraft
CodeHawks
Solodit
Resources