Anyone can vote on proposals on behalf of other users.
There's a function recordVote inside veRAACToken.sol which records votes for a proposal:
As you can see, anyone can call this function with any address as the voter and vote on behalf of someone else.
This vulnerability allows unauthorized users to vote on proposals using the voting power of other users, potentially manipulating outcomes.
Manual Review
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.