MembershipERC1155 lacks transfer restrictions, allowing unrestricted token transfers. This enables unauthorized DAO access, profit manipulation through token splitting, and bypassing of membership controls.
Issue: Missing transfer restrictions in MembershipERC1155 _update() function
Vulnerable Components:
Attack Vectors:
Secondary market trading bypasses DAO controls
Token splitting for profit manipulation
Banned users can simply rebuy tokens
Unrestricted membership transfers
Manipulatable profit distribution
Broken access controls
Bypassed member verification
Manual code review
Add Transfer Restrictions:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.