The Merkle generator encodes each 25 USDC allocation as 25 * 1e18 even though USDC uses six decimals and the deploy script funds only 4 * 25 * 1e6 units. Deploy.s.sol then hardcodes the root generated from those wrong leaves. Correct 25e6 claims fail proof verification, while 25e18 claims exceed the entire funded balance.
makeMerkle.js:7 defines amount = 25 * 1e18. Deploy.s.sol:9 embeds the resulting root 0xf69a...6a05, but line 11 funds only 100e6 token units. The commitment and funded denomination are irreconcilable.
All four intended winners are unable to claim 25 USDC. A 25e6 leaf is not in the tree, and the committed 25e18 transfer cannot be satisfied. The complete airdrop remains locked/unusable.
Use the JavaScript-generated proof with amount 25e6: MerkleProof.verify returns false. Use the same proof with amount 25e18: verification succeeds, but safeTransfer reverts because the contract holds only 100e6. No value permits both verification and a successful intended transfer.
Generate leaves with 25 * 1e6, regenerate tree.json and the root, and update Deploy.s.sol. Add a deployment test that funds exactly 100e6 and proves each of the four 25e6 claims succeeds once.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.