NFT Dealers

First Flight #58
Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: low
Valid

`mintNFT` and `buy` methods are payable for no apparent reason

Root + Impact

Description

mintNft() and buy() are both payable, which allow the callers to send ETH to the contract.

Risk

Even though the interaction of this contract assumes both buyers and sellers to transact in USDC, the payable modifier opens up the possibility for users to set msg.value and send ETH to the contract, with no refund mechanism. Even the contract owner would not be able to withdraw trapped ETH.

Recommended Mitigation

Remove payable modifiers from both mintNft() and buy() methods.

Updates

Lead Judging Commences

rubik0n Lead Judge 16 days ago
Submission Judgement Published
Validated
Assigned finding tags:

accidental-eth-locking

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!