closePot() Can Be Executed Multiple Times Due to Missing Closed StateA contest should be closed exactly once after the 90-day claim period. Once the remaining rewards have been distributed, the Pot should permanently enter a closed state.
closePot() checks whether 90 days have passed, but it never records that the Pot has already been closed.
As a result, the owner can call closePot() multiple times after the 90-day period.
The function also does not set remainingRewards to zero after distributing the rewards.
This allows the contract's internal accounting to continue reporting rewards as available after they have already been distributed.
Likelihood:
The owner can call closePot() any number of times after 90 days.
The contract does not maintain any state indicating that closing has already occurred.
remainingRewards remains unchanged after the first close.
Impact:
Rewards can be distributed repeatedly.
Internal accounting becomes inconsistent with the actual token balance.
Additional funds sent to the Pot can potentially be consumed by subsequent closePot() calls.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.