The contract uses _mint
instead of _safeMint
in GivingThanks::donate
for NFT minting operations. This bypasses checks for whether the recipient can handle ERC721 tokens.
Tokens could be minted to contracts that don't support ERC721, leading to permanent loss of NFTs
Violates ERC721 safety best practices
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.