The GaugeController
contract defines a VOTE_DELAY
constant and tracks lastVoteTime
per user but never enforces the delay between votes, allowing users to vote repeatedly without waiting.
The vote
function never enforces a delay:
Missing delay enforcement allows vote spamming and manipulation.
Add delay enforcement to the vote
function.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.