There is currently no validation on the tier prices when creating a DAO membership, which any verified user can initiate. This allows malicious actors to set abnormally low tier prices, thereby avoiding platform fees. Since these fees are calculated based on the specified tier price, a near-zero price results in no fees being charged. This loophole allows unauthorized usage of platform resources without the intended payment. Additionally, malicious actors face minimal risk, as they only incur gas fees without risking their own funds.
In the createNewDAOMembership function, there is no minimum check on the tier price.
The lack of validation enables exploitation of platform resources without payment, affecting revenue and promoting malicious use.
Implement a minimum tier price check in createNewDAOMembership.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.