Users can repeatedly claim airdrops draining NFT supply.
Normal Behavior: Users should claim airdrop only once
Issue: Contract sets claimed status after processing but never checks it
Likelihood:
Exploitable immediately after first successful claim
Requires no special privileges
Impact:
Infinite NFT claims per user
Exhaustion of NFT supply
Theft of unclaimed allocations
Explanation: The same user can claim multiple times with identical parameters since the claimed status check is missing before processing.
Explanation: Prevents duplicate claims by checking status before processing.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.