Description: The WinningToken::mint
function in the WinningToken contract is only protected by onlyOwner
, but there's no mechanism to prevent the owner from minting unlimited tokens.
Impact: The owner could mint an unlimited number of tokens, potentially devaluing the token and disrupting the game's economy.
Proof of Concept:
Recommended Mitigation:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.