SantasList::collectPresent() enables unlimited free presents via buyPresent()collectPresent() violates the checks-effects-interactions pattern for EXTRA_NICE collectors. It calls _mintAndIncrement() — which uses OpenZeppelin's _safeMint, an external interaction that invokes onERC721Received on the recipient if it is a contract — before it mints the caller's SantaToken reward. Because neither collectPresent() nor buyPresent() carries a reentrancy guard, and because buyPresent() can already be called by anyone against any token holder with no consent ([H-03]), an attacker contract can use the onERC721Received callback fired mid-collectPresent() to reenter buyPresent() and mint itself additional presents by burning other users' SantaToken balances — all before its own original collectPresent() call has even finished.
Impact: High — compounds directly with [H-03] to allow repeated, uninterrupted draining and minting within a single transaction.
Likelihood: Medium — requires the attacker to deploy a contract implementing onERC721Received and to already hold NICE/EXTRA_NICE status, but no other privilege or special protocol state is needed.
Foundry test function to prove the vulnerability.
(Called after warping past CHRISTMAS_2023_BLOCK_TIME, with the attacker contract already checked as NICE/EXTRA_NICE and victim pre-funded with SantaToken.)
Add a reentrancy guard to both externally-reachable, state-changing entry points.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.