The test suite lacks coverage for several critical vulnerabilities present in the contracts.
No tests exist for high-severity issues like the withdrawAllFailedCredits theft vulnerability, NFT burn authorization bypass, or reentrancy attacks.
Likelihood:
Critical bugs go undetected without test coverage
Vulnerabilities reach production unnoticed
Impact:
False confidence in contract security
Critical vulnerabilities remain undetected
Potential for significant financial losses
Add comprehensive test coverage for all identified vulnerabilities:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.