The SantaToken constructor accepts an address santasList parameter without validating it is non-zero. If deployed with address(0), all functions depending on i_santasList become unusable.
Likelihood:
Occurs if deployer passes address(0)
No revert/guard against invalid input
Impact:
Contract becomes permanently unusable
burn/mint functions revert on i_santasList access
Files: src/SantaToken.sol:17
Severity: Low
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.