Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: high
Valid

Funds will be stucked inside RAACNFT when mint function is called.

Vulnerability Details

No function inside RAACNFT to withdraw funds deposited by the user while minting houseNFT.

Impact

When a user wants to mint a houseNFT, he calls RAACNFT::mint. Inside this function we are transferring the price of nft from msg.sender to RAACNFT contract. There is no function to withdraw these funds, so these funds will be stuck inside the contract.

Tools Used

Manual Review

Recommendations

Implement a permissioned function to withdraw these funds.

Updates

Lead Judging Commences

inallhonesty Lead Judge 4 months ago
Submission Judgement Published
Validated
Assigned finding tags:

RAACNFT collects payment for NFT minting but lacks withdrawal functionality, permanently locking all tokens in the contract

inallhonesty Lead Judge 4 months ago
Submission Judgement Published
Validated
Assigned finding tags:

RAACNFT collects payment for NFT minting but lacks withdrawal functionality, permanently locking all tokens in the contract

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.