Expected behavior: transfer_record_only
should confirm that the from
address matches the current owner before updating.
Issue: No assertion is made, so the function decrements from
’s count even if they are not the actual owner.
Likelihood:
Can occur anytime this function is called with mismatched arguments.
More likely in future integrations or refactors.
Impact:
Corrupted state (wrong counts, wrong owners).
Silent asset misattribution.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.