A contest should normally be funded once with its configured totalRewards.
fundContest() does not record that a contest has already been funded.
Therefore, the owner can call:
multiple times.
Every call transfers the full totalRewards amount into the same Pot.
However, remainingRewards inside the Pot is initialized only once and does not increase when additional tokens are deposited.
Likelihood:
fundContest() has no one-time funding restriction.
The owner can invoke the function repeatedly.
Impact:
Extra tokens become unaccounted-for.
Closing logic can operate on stale accounting.
Repeated funding can interact with repeated closing to create unexpected distributions.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.