The function receiveMarketFee(...) is vulnerable to reentrancy attacks due to external calls before state updates.
The function calls transferFrom before updating state, allowing potential reentrancy.
A malicious token could re-enter contract functions before state updates are finalized.
Double-counting or bypassing supply checks, leading to potential fund loss.
Manual code review.
Implement reentrancy guards.
Update state before making external calls.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.