An attackers can call the function unlimited time and can mint all the eggs in the thresholds range i.e 20 percent. Since there's no economic barrier or rate limit, this makes it possible to mint all the NFTs and exploit the egg vault or in-game rewards.
Here you can see that the user have no limit to mint the eggs for a particular address so attacker can mint all the eggs which is unfair for others.
Attackers can mint unlimited eggs (NFTs) at zero cost.
Leaderboards and vault rewards can be manipulated.
Loss of trust in game mechanics.
Incentive system collapse due to unlimited minting.
Manual Review
Limit number of eggs per player or per block
Insecure methods to generate pseudo-random numbers
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.