Public Randomness Function Allows Arbitrary Self-Registration + High Impact
The get_random_slice()
function should be an internal utility called only by authorized registration functions
Instead, it's exposed as a public entry point allowing any user to bypass proper registration and assign themselves random airdrop amounts
Likelihood:
The public entry function is discoverable and callable by any network participant
No authentication mechanism prevents unauthorized calls to this function
Impact:
Complete circumvention of the owner-controlled registration process
Unauthorized users can drain the airdrop pool by self-registering and claiming
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.