Location
Issue
Multiple sign-ups or repeated deposits from the same address are allowed. This is presumably desired (e.g., “GenerousAdditionalContribution”), but it can create confusion about who is truly participating at which deposit.
Impact
Not necessarily a security hole, but the logic around “NewSignup” vs. “GenerousAdditionalContribution” might cause confusion in front-end or analytic tools if not carefully tracked.
Recommendation
Keep as-is but clarify in documentation and event monitoring that participants can deposit multiple times.
Alternatively, rename events for clarity or track first-time deposit vs. subsequent donations more distinctly.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.