AirDropper

AI First Flight #5
Beginner FriendlyDeFiFoundry
EXP
View results
Submission Details
Impact: low
Likelihood: low
Invalid

The claim function allows any address to claim tokens on behalf of another account.

The claim function allows any address to submit a valid Merkle proof and claim tokens on behalf of another account. While the tokens are safely transferred to the correct account, the lack of msg.sender validation means third parties can force claims for other users. This might be intentional, but if not, it could lead to unexpected claim executions.

Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge 4 days ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!