mintEgg in the EggstravaganzaNFT Contract doesn’t verify if tokenId already exists. ERC-721 requires unique token IDs, but if the caller (e.g., EggHuntGame) passes a duplicate tokenId, it will overwrite the existing token’s ownership via _mint.
Loss of uniqueness
potential overwrite of existing NFTs.
Use _safeMint with an internal counter or check _exists(tokenId) before minting
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.