The primary goal of the _refundERC20
function is to refund ERC20 tokens to a specified address.
Function not follow the CEI pattern.
Incorrect balance for ERC20 tokens. It is noted that this function is used in the refund
function, but the refund
function has an incorrect implementation for reentrancy. Alternatively, it could be used in a different function without this modifier and it is field for futher attacks.
manual review
Please consider change _refundERC20
function.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.