Vyper Vested Claims

First Flight #34
Beginner FriendlyDeFi
100 EXP
View results
Submission Details
Severity: low
Invalid

Front-running claims via permissionless claim function

Summary : Front-running claims via permissionless claim function

Vulnerability Details: Anyone can claim for any user, enabling front-running to affect transaction ordering

Impact: Low. UX issue with no direct fund loss

Tools Used: Manual code review

Recommendations: Restrict claim to msg.sender unless third-party claiming is intentional

Updates

Appeal created

bube Lead Judge 4 months ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.