In the current implementation of the buyPass
function, there is no restriction on the number of passes a single user can purchase.
This enables a single wallet to monopolize pass types (e.g., VIP, BACKSTAGE), potentially farming welcome bonuses or gaining unfair access to benefits like performance rewards multipliers.
Likelihood:
Any user can purchase passes repeatedly without restriction.
Users motivated by token rewards or status could exploit this to farm welcome bonuses or gain priority access.
Impact:
Breaks fairness assumptions — festival access meant to be exclusive (e.g., limited VIP slots) becomes meaningless.
Allows gaming of BEAT token system, especially for BACKSTAGE passes that mint more tokens.
Could impact tokenomics or pass resale markets if abused.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.