Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
DatingDapp
Submissions
AI First Flight
DatingDapp
AI First Flight #6
Beginner Friendly
Foundry
Solidity
NFT
EXP
AI First Flight
EXP
Apr 17th, 2026 → Apr 20th, 2026
View repo
View results
8 / 8
Submissions
Severity
Validity
Tags
Author
#1
`tokenURI` returns a raw Base64 blob — missing `data:application/json;base64,` prefix
High
Invalid
web3mio
#2
`userBalances` never credited in `likeUser` — all match rewards are zero and all ETH is permanently locked
High
Valid
[H-01] After the user calls...
web3mio
#3
Re-entrancy in `mintProfile` via `_safeMint` callback mints multiple tokens to one address
Medium
Valid
[M-04] Reentrancy in `Soulb...
web3mio
#4
blockProfile` does not actually block — blocked and self-burned users can re-enter freely
Medium
Valid
[M-01] `SoulboundProfileNFT...
web3mio
#5
blockProfile` does not actually block — blocked and self-burned users can re-enter freely
Medium
Valid
[M-01] `SoulboundProfileNFT...
web3mio
#6
No refund mechanism for unmatched likes — ETH permanently locked
Medium
Invalid
web3mio
#7
No refund mechanism for unmatched likes — ETH permanently locked
High
Valid
[H-01] After the user calls...
web3mio
#8
Ghost likes from burned profiles persist in `likes` mapping — stale likes trigger unexpected matches
Low
Invalid
web3mio
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!