DAO creator can be frontrunned by another user and register a DAO with the same ENS name effectively stopping the first user.
The require
statement checks for provided ENS name, but everyone can provide whatever ENS name it wants. Thus registering an ENS name that it doesnt own.
Real owners of ENS name cant register a DAO
manual
Use ENSRegistry
or ENSRoot
contract to check if msg.sender is owner of the ensname
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.