The system is designed so that each festival pass can attend each performance only once, with a 1-hour cooldown between any performance attendances to prevent rapid farming of BEAT token rewards.
However, attendance tracking is tied to user addresses rather than pass tokens, allowing the same pass to attend the same performance multiple times through strategic transfers between addresses.
Likelihood:
Users can easily transfer ERC1155 passes to other addresses they control or collaborate with others
The attack requires no special technical knowledge, just basic understanding of NFT transfers
Economic incentive exists as users can earn multiple BEAT token rewards from single pass purchase
Impact:
Same pass can attend same performance unlimited times through different addresses, breaking the one-attendance-per-pass design
Cooldown mechanism can be bypassed by transferring passes between addresses
Excessive BEAT token minting beyond intended tokenomics, potentially devaluing the token
Unfair advantage for users who can afford multiple addresses or collaborate with others
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.