The blockProfile
function in SoulboundProfileNFT
allows the contract owner to block/delete a user's profile. The owner has to be trusted to not block a user's profile when the user is still an active user of the protocol
The owner can delete a user's profile, leading to the loss of the user's profile leaving them unable to use the protocol
Manual review
Please read the CodeHawks documentation to know which submissions are valid. If you disagree, provide a coded PoC and explain the real likelyhood and the detailed impact on the mainnet without any supposition (if, it could, etc) to prove your point.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.