In claimFaucetTokens, returning claimers trigger else branch, resetting dailyDrips to 0. This bypasses daily cap for subsequent first-timers, enabling excess ETH distribution.
Likelihood:
Returning users claim mid-day.
Coordinated attacks with alts.
Impact:
Exceeds ETH cap, drains funds.
Undermines daily limits.
POC Explanation: User1 claims as first-timer, warps 4 days to return. 90 first-timers near cap. User1 reclaims, resets dailyDrips=0. 50 more first-timers exceed cap (total 140 drips > 100), proving bypass and over-drip.
Mitigation Key Points: Remove reset in else. Cap enforced continuously. Prevents bypass; no impact on returning claims.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.