trickOrTreat
function for trick scenario.Description:
If user can predict when trick scenario will occur, they can send zero value with the trickOrTreat
function call and add the minted NFT to the pending list. Repeating this will lead to spamming of the pending list.
Recommended Mitigation:
As the function returns the excess funds, a check can be added in the beginning to allow value amounts greater than treat cost only.
The protocol can work correctly with more than 20000 tokens in it. It is informational.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.