A person who wins the auction can still able to withdraw his bid tokens instead of sending this amount to the protocol owner
By this issue an attack will tries to win the auction by placing bids with higher higher amounts. As anyways at the end he will still able to withdraw his bid tokens
The protocol owner cannot able to get the highest bid amount value after the completion of the auction
Manual Inspection
Also add check by not allowing users to claim mutliple times
The `withdraw` function allows the participants to receive back the value of all their unsuccessful bids. The problem is that the winner of the auction will receive all bids including the `highest_bid` that should be paid to the NFT owner.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.