Project

One World
NFTDeFi
15,000 USDC
View results
Submission Details
Severity: low
Invalid

unsafe use of ecrecover

Summary

there is the use of raw ecrecover in the contracts, this function is susceptible to replay attacks and signature malleability. This function also returns random addresses or zero addresses for invalid signatures.

Recommendations

consider using openzeppelin ECDSA library

Updates

Lead Judging Commences

0xbrivan2 Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.