Malicious actors can mint unlimited NFTs without staking tokens.
Normal Behavior: Only SnowmanAirdrop should mint NFTs after token verification
Issue: No access control allows anyone to call mint function directly
Likelihood:
Exploitable immediately after deployment
Requires no special privileges or conditions
Impact:
Infinite NFT supply inflation
Complete devaluation of NFT collection
Protocol economic model collapse
Explanation: Any address can directly mint arbitrary NFTs without interacting with the airdrop contract or staking tokens.
Explanation: Restricts minting to only the designated airdrop contract.
The mint function of the Snowman contract is unprotected. Hence, anyone can call it and mint NFTs without necessarily partaking in the airdrop.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.