The SoulboundProfileNFT contract allows users to create profiles without any verification of identity or uniqueness checks. This enables malicious actors to create profiles impersonating other individuals, potentially leading to fraud and platform abuse.
Name uniqueness validation
Identity verification mechanisms
Profile detail duplication checks
Anti-spoofing measures
Users can create profiles impersonating celebrities, public figures, or other users
Platform credibility and trust are compromised
Potential for fraud and scams increases
User safety and platform integrity are at risk
Manual review
Foundry for POC
Implement profile uniqueness checks:
Scamming/phishing is not the protocol problem, that's a user mistake. NFT are unique, even if someone does a copy of your profile (which is also possible in web2), I consider it informational. Injection is a problem for the web2 part of the protocol, not a bug here. For the age, it depends on the countries law and future medicine. Anyways, that's more an ethical/political problem, not a bug.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.