The SnowmanAirdrop contract verifies off-chain signatures to allow users or third parties to claim Snowman NFTs securely.
The signed message does not include domain-specific data such as the contract address or chain ID. This allows the same valid signature to be replayed across different contracts or chains that implement similar logic.
Likelihood:
Occurs when the same signer key is reused across deployments
Occurs during contract redeployment or cross-chain usage
Impact:
Unauthorized NFT claims in unintended contracts
Signature misuse beyond the signer’s original intent
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.