The protocol specification dictates that creators should only be allowed to withdraw funds once their fundraising campaign succeeds (goal reached).
However, the withdraw() function contains zero validation checks regarding fund.goal or fund.deadline. A creator can call withdraw() immediately after any contributor deposits SOL, stealing the funds even if the campaign raised far less than the required goal or before the campaign deadline has elapsed.
Likelihood:
High. Any malicious or premature creator can execute withdraw() at any moment during an active campaign.
Impact:
High. Theft of contributor funds on failed or incomplete campaigns. Contributors are deprived of their promised refunds on unsuccessful fundraisers.
A campaign is created with a 1,000 SOL goal. A contributor deposits 10 SOL. The creator immediately calls withdraw(), draining the 10 SOL even though the campaign is far from reaching its target.
Ensure withdraw() verifies that the campaign has reached or exceeded its funding goal.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.