Snowman Merkle Airdrop

AI First Flight #10
Beginner FriendlyFoundrySolidityNFT
EXP
View results
Submission Details
Severity: low
Valid

Snow.s_earnTimer is a single global variable instead of per-user - any address freely locks every other user out of free earning

Root + Impact

Description

  • Normal behavior: Snow is meant to be earnable free once a week, per user.

  • s_earnTimer is one uint256 for the whole contract, not per-address. The moment any one address calls earnSnow or buySnow, every other address is locked out for a week — including addresses that have never called earnSnow before.

// src/Snow.sol
@> uint256 private s_earnTimer; // ONE slot for the whole contract, not per-user
...
function earnSnow() external canFarmSnow {
if (s_earnTimer != 0 && block.timestamp < (s_earnTimer + 1 weeks)) revert S__Timer();
_mint(msg.sender, 1);
@> s_earnTimer = block.timestamp; // resets the shared timer for every address
}

buySnow also resets this timer unconditionally and never checks it, and has no minimum-amount guard — buySnow(0) resets it for free, with no wait and no funds.

Risk

Likelihood:

  • This is the automatic outcome of two unrelated users using the free-earn feature in the same week — the project's own script/Helper.s.sol inserts vm.warp(+1 weeks) between every different test user's earnSnow() call to avoid triggering it.

  • buySnow(0) removes even the "wait out your own cooldown" cost — callable every block, at zero ETH/WETH/Snow.

Impact:

  • The free-earn path is one of two ways to acquire Snow, and this bug takes it fully offline for everyone but the weekly race-winner, for the whole 12-week farming window.

  • CodeHawks' High-impact definition is disjunctive (funds at risk or severe disruption of protocol functionality/availability) — this clears the availability clause alone.

Proof of Concept

// test/PoC_GlobalEarnTimerDoS.t.sol
function test_OneUsersFreeEarnLocksOutEveryOtherUser() public {
vm.prank(alice);
snow.earnSnow();
vm.prank(bob); // bob has NEVER called earnSnow before
vm.expectRevert(Snow.S__Timer.selector);
snow.earnSnow(); // reverts anyway
}
function test_BuySnowZeroIsAFreeInstantTimerResetWithNoWaitAndNoCost() public {
vm.prank(bob);
snow.earnSnow();
vm.warp(block.timestamp + 1 weeks); // bob legitimately due again
vm.prank(griefer);
snow.buySnow(0); // resets shared timer: no ETH, no WETH, no wait
vm.prank(bob);
vm.expectRevert(Snow.S__Timer.selector);
snow.earnSnow(); // locked out again anyway
}

forge test -vvvv:

[PASS] test_OneUsersFreeEarnLocksOutEveryOtherUser() (gas: 113897)
[PASS] test_BuySnowZeroIsAFreeInstantTimerResetWithNoWaitAndNoCost() (gas: 121677)
├─ Snow::buySnow(0) [zero_cost_griefer]
│ └─ emit SnowBought(buyer: zero_cost_griefer, amount: 0)
├─ Snow::balanceOf(zero_cost_griefer) → 0
├─ Snow::earnSnow() [bob]
│ └─ ← [Revert] S__Timer()
Suite result: ok. 3 passed; 0 failed; 0 skipped

Recommended Mitigation

Scope the timer per user instead of sharing one slot contract-wide:

- uint256 private s_earnTimer;
+ mapping(address => uint256) private s_earnTimer;
...
function earnSnow() external canFarmSnow {
- if (s_earnTimer != 0 && block.timestamp < (s_earnTimer + 1 weeks)) revert S__Timer();
+ uint256 last = s_earnTimer[msg.sender];
+ if (last != 0 && block.timestamp < last + 1 weeks) revert S__Timer();
_mint(msg.sender, 1);
- s_earnTimer = block.timestamp;
+ s_earnTimer[msg.sender] = block.timestamp;
}

Also require amount > 0 in buySnow so a zero-value call can't touch state for free.

Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge about 3 hours ago
Submission Judgement Published
Validated
Assigned finding tags:

[L-02] Global Timer Reset in Snow::buySnow Denies Free Claims for All Users

## Description: The `Snow::buySnow` function contains a critical flaw where it resets a global timer `(s_earnTimer)` to the current block timestamp on every invocation. This timer controls eligibility for free token claims via `Snow::earnSnow()`, which requires 1 week to pass since the last timer reset. As a result: Any token purchase `(via buySnow)` blocks all free claims for all users for 7 days Malicious actors can permanently suppress free claims with micro-transactions Contradicts protocol documentation promising **"free weekly claims per user"** ## Impact: * **Complete Denial-of-Service:** Free claim mechanism becomes unusable * **Broken Protocol Incentives:** Undermines core user acquisition strategy * **Economic Damage:** Eliminates promised free distribution channel * **Reputation Harm:** Users perceive protocol as dishonest ```solidity function buySnow(uint256 amount) external payable canFarmSnow { if (msg.value == (s_buyFee * amount)) { _mint(msg.sender, amount); } else { i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount)); _mint(msg.sender, amount); } @> s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` ## Risk **Likelihood**: • Triggered by normal protocol usage (any purchase) • Requires only one transaction every 7 days to maintain blockage • Incentivized attack (low-cost disruption) **Impact**: • Permanent suppression of core protocol feature • Loss of user trust and adoption • Violates documented tokenomics ## Proof of Concept **Attack Scenario:** Permanent Free Claim Suppression * Attacker calls **buySnow(1)** with minimum payment * **s\_earnTimer** sets to current timestamp (T0) * All **earnSnow()** calls revert for **next 7 days** * On day 6, attacker repeats **buySnow(1)** * New timer reset (T1 = T0+6 days) * Free claims blocked until **T1+7 days (total 13 days)** * Repeat step **4 every 6 days → permanent blockage** **Test Case:** ```solidity // Day 0: Deploy contract snow = new Snow(...); // s_earnTimer = 0 // UserA claims successfully snow.earnSnow(); // Success (first claim always allowed) // Day 1: UserB buys 1 token snow.buySnow(1); // Resets global timer to day 1 // Day 2: UserA attempts claim snow.earnSnow(); // Reverts! Requires day 1+7 = day 8 // Day 7: UserC buys 1 token (day 7 < day 1+7) snow.buySnow(1); // Resets timer to day 7 // Day 8: UserA retries snow.earnSnow(); // Still reverts! Now requires day 7+7 = day 14 ``` ## Recommended Mitigation **Step 1:** Remove Global Timer Reset from `buySnow` ```diff function buySnow(uint256 amount) external payable canFarmSnow { // ... existing payment logic ... - s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` **Step 2:** Implement Per-User Timer in `earnSnow` ```solidity // Add new state variable mapping(address => uint256) private s_lastClaimTime; function earnSnow() external canFarmSnow { // Check per-user timer instead of global if (s_lastClaimTime[msg.sender] != 0 && block.timestamp < s_lastClaimTime[msg.sender] + 1 weeks ) { revert S__Timer(); } _mint(msg.sender, 1); s_lastClaimTime[msg.sender] = block.timestamp; // Update user-specific timer emit SnowEarned(msg.sender, 1); // Add missing event } ``` **Step 3:** Initialize First Claim (Constructor) ```solidity constructor(...) { // Initialize with current timestamp to prevent immediate claims s_lastClaimTime[address(0)] = block.timestamp; } ```

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!