Summary: Missing nonce validation in token transfers allows replay attacks.
Details: The joinGameWithToken() and other token functions don't validate transfer nonces, allowing malicious users to replay token transfers.
Impact: Could result in duplicate token transfers and game state corruption.
Recommendation: Add nonce tracking:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.