Santa's List

AI First Flight #3
Beginner FriendlyFoundry
EXP
View results
Submission Details
Impact: low
Likelihood: low
Invalid

`SantasList::buyPresent()` burns payment before confirming the present mint succeeds

[L-03] SantasList::buyPresent() burns payment before confirming the present mint succeeds

Description:

buyPresent() burns the payment (i_santaToken.burn(...)) before minting the present (_mintAndIncrement()). Today, Solidity's atomic revert semantics mean the burn cannot persist without the mint also succeeding within the same transaction, so there is no live fund-loss vector. This ordering is nonetheless inconsistent with defensive coding practice: should the two operations ever be split across transactions, wrapped in try/catch, or made non-atomic by a future change (e.g. a cross-chain or relayed flow), a user could have their SantaTokens burned without receiving the corresponding present.

Risk Analysis:

  • Impact: Low — no live fund-loss vector today given full-transaction atomicity.

  • Likelihood: Low — would only become relevant if a future change made the two operations non-atomic.

Proof of Concept:

Not demonstrable today given full-transaction atomicity; included as a defensive-coding observation to flag before any future refactor that could break atomicity.

Recommended Mitigation:

function buyPresent(address presentReceiver) external {
- i_santaToken.burn(presentReceiver);
- _mintAndIncrement();
+ _mintAndIncrement();
+ i_santaToken.burn(msg.sender);
}
Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge 14 days ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!