Normally ,the Organizer creates performances with startTime, duration, and set rewards.
A malicious or careless Organizer could create infinite-durations or high-reward performances.
Likelihood:
When Infinite or very long durations keep the performance active, allowing users to check in over and over again (abusing COOLDOWN
reset).
Extremely high reward values could be used to mint absurd amounts of BEAT with just one check-in.
Impact:
Abuse of reward logic .the createPerformance
function lacks upper bounds on duration
and reward
, which opens up a BEAT farming exploit risk,therefore a malicious attacker could do unlimited BEAT farming, resulting in beat token inflation ,theft ,fraud etc.
Infinite or very long durations keep the performance active, allowing users to check in over and over again (abusing COOLDOWN
reset).This could result in disorder in the festival
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.