Addresses and amounts are concatenated into JSON strings.
Unescaped user inputs allow JSON structure manipulation via special characters.
Likelihood:
Guaranteed if addresses contain " or \
High when using vanity addresses
Certain during fuzz testingImpact:
Impact:
Corrupted JSON output breaking dependent systems
Silent test data misinterpretation
False positive test results
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.