The RAACNFT contract permanently locks crvUSD tokens sent during minting with no withdrawal mechanism.
When users mint NFTs, they send crvUSD tokens to the contract:
However, the contract has:
No function to withdraw these tokens
No way to recover locked funds
No burning mechanism that returns tokens
All crvUSD tokens sent to contract become permanently locked
Loss of user funds
Protocol value becomes inaccessible
HIGH severity due to permanent fund lockup
Manual Review
Add withdrawal functionality for the protocol:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.