Commitment does not bind sender identity, making brute-force and front-running possible.
Commit hash is generated using:
Player can potentially impersonate another commit
Commit reuse across games undermines privacy
Manual review
Change hash to include sender address:
The contract does not enforce salt uniqueness
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.