Trick or Treat

First Flight #27
Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: high
Invalid

Users could potentially lose their funds and not get a treat at all

Summary

Users that don't have extra money to pay if they're unlucky to get double the cost, would end up not being able to recover their money and would not get any treat at all

Vulnerability Details

  • User interacts with trickOrTreat() and unfortunately gets double the cost.

  • User ETH sent wasn't enough to complete transaction

  • User unfortunately doesn't have extra eth to pay.

  • There's no way to recover their eth and would still end up without any treat.

Impact

Loss of User's funds

Tools Used

Manual Code Review

Recommendations

There should be a way for users to recover their money if they are not able to complete payment.

Updates

Appeal created

bube Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.