Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
DatingDapp
Submissions
AI First Flight
DatingDapp
AI First Flight #6
Beginner Friendly
Foundry
Solidity
NFT
EXP
AI First Flight
EXP
Mar 12th, 2026 → Mar 12th, 2026
View repo
View results
10 / 10
Submissions
Severity
Validity
Tags
Author
#1
User deposits are not credited to their balances in likeUser, leading to permanently locked funds.
High
Valid
[H-01] After the user calls...
plarochkin
#2
Reentrancy in mintProfile allows users to bypass the one-profile-per-user restriction.
Medium
Valid
[M-04] Reentrancy in `Soulb...
plarochkin
#3
matchRewards consumes a user's entire aggregated balance for a single match, causing loss of funds for other pending likes.
High
Invalid
plarochkin
#4
Blocked users can bypass the block and immediately remint a new profile.
Medium
Valid
[M-01] `SoulboundProfileNFT...
plarochkin
#5
Approving transactions by array index in MultiSig is vulnerable to front-running.
Medium
Invalid
plarochkin
#6
tokenURI returns base64 encoded JSON without the required data URL scheme prefix.
Low
Invalid
plarochkin
#7
Profile minting is vulnerable to front-running, allowing attackers to copy profile data.
Low
Invalid
plarochkin
#8
Single-step ownership transfer pattern used across contracts.
Low
Invalid
plarochkin
#9
Floating pragma used across contracts.
Low
Invalid
plarochkin
#10
Missing zero-address check in LikeRegistry constructor.
Low
Invalid
plarochkin
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!