External calls before state changes enable reentrancy attacks.
Likelihood:
Requires malicious contract, but common in ETH-based systems
Impact:
Fund theft
unlimited token minting
DoS
Add nonReentrant
modifier from OZ's ReentrancyGuard.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.