Game deadlines rely on block.timestamp
, which miners can manipulate within ~30 seconds.
Location: revealDeadline
and joinDeadline
checks
Issue:
Miners can slightly alter timestamps for advantage
Particularly impactful for high-value games
Minor fairness compromise in time-sensitive actions
Manual Review
Use block.number for critical deadlines
Add buffer times to mitigate miner influence
Code suggestions or observations that do not pose a direct security risk.
Code suggestions or observations that do not pose a direct security risk.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.