The intended behavior of the auction system is that once a valid bid is placed, the auction should run for a total of 3 days before anyone can settle or finalize it.
However, in the current implementation, the auctionEnd time is set using a constant S_AUCTION_EXTENSION_DURATION = 15 minutes, which incorrectly limits the entire auction duration to just 15 minutes after the first bid.
Also if in the 15 minif no one bids then the auction can be bidded by anyone.
Likelihood: HIGH
Every auction created in this system will close just 15 minutes after the first valid bid is placed.
This will consistently occur across all NFTs listed, impacting every auction flow.
Impact: HIGH
Auctions may end before legitimate users have time to place competing bids.
It violates the business logic and user expectation of a 3-day bidding window, which could result in seller losses and legal/compliance risks.
Changing it to 03 days will solve the issue.
Documentation for BidBeasts Marketplace is incomplete or inaccurate, potentially leading to misconfigurations or security misunderstandings.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.