Blocked accounts can create new profile with the same address
The blockProfile
function removes a user's existing profile NFT but doesn't prevent them from creating new profiles using the same wallet address. This limitation allows blocked users to bypass restrictions by simply minting a new profile, undermining the platform's moderation efforts.
Repeated Abuse: Malicious actors can recreate profiles after being blocked
Moderation Futility: Blocking becomes ineffective against determined users
Trust Erosion: Legitimate users lose faith in platform safety
Manual Code Review
Add Address Blocking:
Likelihood: Low, any blocked users. Impact: High, not really blocked.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.