DatingDapp

AI First Flight #6
Beginner FriendlyFoundrySolidityNFT
EXP
View results
Submission Details
Severity: high
Valid

`LikeRegistry::likeUser` never credits `userBalances`, so matched users receive 0 and all like-ETH is locked

Description


likeUserrequires the caller to send at least 1 ETH, but it never records that ETH in userBalances:


function likeUser(address liked) external payable {
require(msg.value >= 1 ether, "Must send at least 1 ETH");
...
likes[msg.sender][liked] = true; // @> records the like
// @> MISSING: userBalances[msg.sender] += msg.value;
if (likes[liked][msg.sender]) {
...
matchRewards(liked, msg.sender);
}
}
```
​
When a mutual like occurs, `matchRewards` pools the two users' balances to fund the match:
​
```solidity
uint256 matchUserOne = userBalances[from]; // @> always 0
uint256 matchUserTwo = userBalances[to]; // @> always 0
...
uint256 totalRewards = matchUserOne + matchUserTwo; // @> 0
MultiSigWallet multiSigWallet = new MultiSigWallet(from, to);
(bool success,) = payable(address(multiSigWallet)).call{value: rewards}(""); // @> sends 0
```
​
Because `userBalances` is never incremented, `totalRewards` (and the fees) are always `0`. The 1+ ETH that each user actually paid sits in the `LikeRegistry` contract and is **never pooled into the match's multisig** and never returned.
​
## Risk
​
**Likelihood: High**
​
- Occurs on every like/match — the core, intended flow of the protocol. No special conditions.
​
**Impact: High**
​
- Matched users receive nothing (their multisig is funded with 0), and every ETH paid to `likeUser` accumulates in `LikeRegistry` with no way to retrieve it (users have no withdraw function; `withdrawFees` only sends `totalFees`, which is also 0). Permanent, total loss/lock of all user funds — the protocol's entire value proposition is broken.
​
## Proof of Concept
​
```solidity
// Alice likeUser(Bob){value: 1 ether} -> userBalances[Alice] stays 0, contract holds 1 ETH
// Bob likeUser(Alice){value: 1 ether} -> mutual match -> matchRewards(Alice,Bob)
// matchUserOne = userBalances[Alice] = 0; matchUserTwo = userBalances[Bob] = 0
// totalRewards = 0 -> multisig funded with 0; the 2 ETH stays stuck in LikeRegistry forever.
```
​
## Recommended Mitigation
​
Credit the sender's balance when they like:
​
```solidity
function likeUser(address liked) external payable {
require(msg.value >= 1 ether, "Must send at least 1 ETH");
...
userBalances[msg.sender] += msg.value; // @> record the deposit
likes[msg.sender][liked] = true;
...
}
```
}
}
}
Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge about 2 hours ago
Submission Judgement Published
Validated
Assigned finding tags:

[H-01] After the user calls the `likeUser` function, the userBalance does not increase by the corresponding value.

## Description User A calls `likeUser` and sends `value > 1` ETH. According to the design of DatingDapp, the amount for user A should be accumulated by `userBalances`. Otherwise, in the subsequent calculations, the balance for each user will be 0. ## Vulnerability Details When User A calls `likeUser`, the accumulation of `userBalances` is not performed. ```solidity function likeUser( address liked ) external payable { require(msg.value >= 1 ether, "Must send at least 1 ETH"); require(!likes[msg.sender][liked], "Already liked"); require(msg.sender != liked, "Cannot like yourself"); require(profileNFT.profileToToken(msg.sender) != 0, "Must have a profile NFT"); require(profileNFT.profileToToken(liked) != 0, "Liked user must have a profile NFT"); likes[msg.sender][liked] = true; emit Liked(msg.sender, liked); // Check if mutual like if (likes[liked][msg.sender]) { matches[msg.sender].push(liked); matches[liked].push(msg.sender); emit Matched(msg.sender, liked); matchRewards(liked, msg.sender); } } ``` This will result in `totalRewards` always being 0, affecting all subsequent calculations: ```solidity uint256 totalRewards = matchUserOne + matchUserTwo; uint256 matchingFees = (totalRewards * FIXEDFEE ) / 100; uint256 rewards = totalRewards - matchingFees; totalFees += matchingFees; ``` ## POC ```solidity function testUserBalanceshouldIncreaseAfterLike() public { vm.prank(user1); likeRegistry.likeUser{value: 20 ether}(user2); assertEq(likeRegistry.userBalances(user1), 20 ether, "User1 balance should be 20 ether"); } ``` Then we will get an error: ```shell [FAIL: User1 balance should be 20 ether: 0 != 20000000000000000000] ``` ## Impact - Users will be unable to receive rewards. - The contract owner will also be unable to withdraw ETH from the contract. ## Recommendations Add processing for `userBalances` in the `likeUser` function: ```diff function likeUser( address liked ) external payable { require(msg.value >= 1 ether, "Must send at least 1 ETH"); require(!likes[msg.sender][liked], "Already liked"); require(msg.sender != liked, "Cannot like yourself"); require(profileNFT.profileToToken(msg.sender) != 0, "Must have a profile NFT"); require(profileNFT.profileToToken(liked) != 0, "Liked user must have a profile NFT"); likes[msg.sender][liked] = true; + userBalances[msg.sender] += msg.value; emit Liked(msg.sender, liked); [...] } ```

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!