Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: medium
Invalid

Open Claim Function (Caller ≠ User)

What we see:


• The claimRewards(address user) function does not require that msg.sender equals the user argument.

issue:
Although rewards are always sent to the specified user, this design means anyone may trigger a claim on behalf of another user. While this doesn’t steal funds (since tokens are transferred to the user’s address), it might lead to unexpected gas expenditures or could be used to spam claim-triggering calls.

Impact:
Minor nuisance and potential for unwanted extra transactions—but not a direct loss of funds.

Updates

Lead Judging Commences

inallhonesty Lead Judge 7 months ago
Submission Judgement Published
Invalidated
Reason: Lack of quality

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!