SantasList::buyPresent() burns payment before confirming the present mint succeedsbuyPresent() burns the payment (i_santaToken.burn(...)) before minting the present (_mintAndIncrement()). Today, Solidity's atomic revert semantics mean the burn cannot persist without the mint also succeeding within the same transaction, so there is no live fund-loss vector. This ordering is nonetheless inconsistent with defensive coding practice: should the two operations ever be split across transactions, wrapped in try/catch, or made non-atomic by a future change (e.g. a cross-chain or relayed flow), a user could have their SantaTokens burned without receiving the corresponding present.
Impact: Low — no live fund-loss vector today given full-transaction atomicity.
Likelihood: Low — would only become relevant if a future change made the two operations non-atomic.
Not demonstrable today given full-transaction atomicity; included as a defensive-coding observation to flag before any future refactor that could break atomicity.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.