Snowman Merkle Airdrop

AI First Flight #10
Beginner FriendlyFoundrySolidityNFT
EXP
View results
Submission Details
Severity: low
Valid

Global Snow::s_earnTimer allows any user to block another user's first-ever free earnSnow() claim

Root + Impact

Description

  • Each address should be entitled to its own independent weekly allowance of free Snow tokens via earnSnow(), regardless of when or how often other addresses call the function. One user's activity should never affect another user's ability to claim their own weekly allowance.

  • s_earnTimer is declared as a single, global uint256 rather than a per-address mapping. Because every successful call to earnSnow() (and every call to buySnow()) overwrites this same shared variable, the moment any one address calls earnSnow() successfully, every other address, including one that has never called the function before, is blocked from calling it for a full week, purely because of a stranger's unrelated transaction.

@> uint256 private s_earnTimer;
@> // single global timer shared by every user, instead of mapping(address => uint256)
function earnSnow() external canFarmSnow {
if (s_earnTimer != 0 && block.timestamp < (s_earnTimer + 1 weeks)) {
revert S__Timer();
}
_mint(msg.sender, 1);
@> s_earnTimer = block.timestamp; // this resets the same timer for every address, not just msg.sender
}

Risk

Likelihood: High

  • This is the default outcome the moment more than one address interacts with earnSnow() within the same week, which is expected, ordinary usage of the contract's core free-farming feature.

  • A malicious actor can deliberately call earnSnow() the instant the cooldown expires each week, at near-zero cost (gas only), to guarantee they reset the shared timer before any other user and lock every other address out of the free-farming feature for the entire following week, repeatable across the full 12-week farming period.

Impact:

  • The free-farming mechanic cannot function as a per-user weekly allowance for more than one address at a time, even under entirely honest, non-adversarial use — two ordinary users acting in good faith will interfere with each other purely by chance.

  • The mechanic is trivially and cheaply griefable: an attacker can sustain a denial-of-service against the entire free-farming feature for all other users across the whole 12-week farming window, at the cost of only gas.

Proof of Concept

function testGlobalEarnTimerBlocksOtherUsers() public {
// Ashley earns first
vm.prank(ashley);
snow.earnSnow();
assert(snow.balanceOf(ashley) == 1);
// Victory tries to earn shortly after but is blocked because the earn timer is global, not per-user
vm.warp(block.timestamp + 1 days);
vm.prank(victory);
vm.expectRevert(Snow.S__Timer.selector);
snow.earnSnow();
// Victory's balance stays at 0 cause she can't claim anything
assert(snow.balanceOf(victory) == 0);
// After 1 week, victory can now earn
vm.warp(block.timestamp + 1 weeks);
vm.prank(victory);
snow.earnSnow();
assert(snow.balanceOf(victory) == 1);
}

This test demonstrates that victory, an address that has never called earnSnow() before, is incorrectly blocked with S__Timer() purely because ashley, a completely unrelated address, called earnSnow() one day earlier. Running forge test --mt testGlobalEarnTimerBlocksOtherUsers confirms this passes: victory's legitimate first attempt reverts, and victory only succeeds a full week after ashley's call — not after victory's own (nonexistent) prior call.

function invariant_firstTimeCallersNeverBlocked() public view {
assertFalse(
handler.anyFirstAttemptWronglyReverted(),
"A genuine first-time caller was blocked from earnSnow() due to another user's activity"
);
}

This invariant is checked by a companion handler contract that repeatedly calls earnSnow() from a pool of ten distinct, never-before-used addresses, in random order, tracking whether any address's genuine first-ever attempt was wrongly reverted due to another address's prior success. Foundry's fuzzer broke this invariant after just two calls: one address succeeding, followed immediately by a second, entirely different address being blocked on its first-ever attempt — independently confirming the exploit with the minimal possible reproduction.

Recommended Mitigation

This mitigation replaces the single global uint256 with a mapping(address => uint256), so each address's cooldown is tracked and enforced entirely independently of every other address's activity. The buySnow() function, which also currently writes to the shared timer, would need the equivalent change (s_earnTimer[msg.sender] = block.timestamp;) for consistency, ensuring a user's own purchase only affects their own future earnSnow() cooldown, never another user's.

- uint256 private s_earnTimer;
+ mapping(address => uint256) private s_earnTimer;
function earnSnow() external canFarmSnow {
- if (s_earnTimer != 0 && block.timestamp < (s_earnTimer + 1 weeks)) {
+ if (s_earnTimer[msg.sender] != 0 && block.timestamp < (s_earnTimer[msg.sender] + 1 weeks)) {
revert S__Timer();
}
_mint(msg.sender, 1);
- s_earnTimer = block.timestamp;
+ s_earnTimer[msg.sender] = block.timestamp;
}
Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge about 8 hours ago
Submission Judgement Published
Validated
Assigned finding tags:

[L-02] Global Timer Reset in Snow::buySnow Denies Free Claims for All Users

## Description: The `Snow::buySnow` function contains a critical flaw where it resets a global timer `(s_earnTimer)` to the current block timestamp on every invocation. This timer controls eligibility for free token claims via `Snow::earnSnow()`, which requires 1 week to pass since the last timer reset. As a result: Any token purchase `(via buySnow)` blocks all free claims for all users for 7 days Malicious actors can permanently suppress free claims with micro-transactions Contradicts protocol documentation promising **"free weekly claims per user"** ## Impact: * **Complete Denial-of-Service:** Free claim mechanism becomes unusable * **Broken Protocol Incentives:** Undermines core user acquisition strategy * **Economic Damage:** Eliminates promised free distribution channel * **Reputation Harm:** Users perceive protocol as dishonest ```solidity function buySnow(uint256 amount) external payable canFarmSnow { if (msg.value == (s_buyFee * amount)) { _mint(msg.sender, amount); } else { i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount)); _mint(msg.sender, amount); } @> s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` ## Risk **Likelihood**: • Triggered by normal protocol usage (any purchase) • Requires only one transaction every 7 days to maintain blockage • Incentivized attack (low-cost disruption) **Impact**: • Permanent suppression of core protocol feature • Loss of user trust and adoption • Violates documented tokenomics ## Proof of Concept **Attack Scenario:** Permanent Free Claim Suppression * Attacker calls **buySnow(1)** with minimum payment * **s\_earnTimer** sets to current timestamp (T0) * All **earnSnow()** calls revert for **next 7 days** * On day 6, attacker repeats **buySnow(1)** * New timer reset (T1 = T0+6 days) * Free claims blocked until **T1+7 days (total 13 days)** * Repeat step **4 every 6 days → permanent blockage** **Test Case:** ```solidity // Day 0: Deploy contract snow = new Snow(...); // s_earnTimer = 0 // UserA claims successfully snow.earnSnow(); // Success (first claim always allowed) // Day 1: UserB buys 1 token snow.buySnow(1); // Resets global timer to day 1 // Day 2: UserA attempts claim snow.earnSnow(); // Reverts! Requires day 1+7 = day 8 // Day 7: UserC buys 1 token (day 7 < day 1+7) snow.buySnow(1); // Resets timer to day 7 // Day 8: UserA retries snow.earnSnow(); // Still reverts! Now requires day 7+7 = day 14 ``` ## Recommended Mitigation **Step 1:** Remove Global Timer Reset from `buySnow` ```diff function buySnow(uint256 amount) external payable canFarmSnow { // ... existing payment logic ... - s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` **Step 2:** Implement Per-User Timer in `earnSnow` ```solidity // Add new state variable mapping(address => uint256) private s_lastClaimTime; function earnSnow() external canFarmSnow { // Check per-user timer instead of global if (s_lastClaimTime[msg.sender] != 0 && block.timestamp < s_lastClaimTime[msg.sender] + 1 weeks ) { revert S__Timer(); } _mint(msg.sender, 1); s_lastClaimTime[msg.sender] = block.timestamp; // Update user-specific timer emit SnowEarned(msg.sender, 1); // Add missing event } ``` **Step 3:** Initialize First Claim (Constructor) ```solidity constructor(...) { // Initialize with current timestamp to prevent immediate claims s_lastClaimTime[address(0)] = block.timestamp; } ```

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!