Under normal behavior, the ERC20 token used for payments must enforce strict minting controls so users can only spend legitimately acquired funds.
MockUSDC allows any address to mint arbitrary token amounts, enabling attackers to fabricate unlimited balance and purchase NFTs or extract marketplace value without real cost.
Likelihood:
Occurs whenever MockUSDC is used outside a strictly controlled test environment.
Happens during normal mint calls with no access restrictions.
Impact:
Attacker can mint unlimited funds and buy NFTs for free.
Marketplace economic guarantees are completely broken.
Restrict minting to a privileged role
Explicitly mark token as test-only
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.