Normal behavior: Marketplace fees should apply on every sale based on price thresholds.
The current logic allows a buyer to buy an NFT, then relist and self-transfer in ways that bypass or miscalculate fees, enabling a fee bypass chain.
Likelihood:
Occurs on normal marketplace flows: buy → relist → buy → cancel.
No privileged access required.
Impact:
Attacker can artificially inflate price or avoid fees
Marketplace loses revenue
Store sale price history separate from listing data and block price manipulations that avoid fee tiers.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.