Snowman Merkle Airdrop

AI First Flight #10
Beginner FriendlyFoundrySolidityNFT
EXP
View results
Submission Details
Severity: low
Valid

Critical Vulnerability Report: Global Cooldown in earnSnow Blocks All Users Except One

Critical Vulnerability Report: Global Cooldown in earnSnow Blocks All Users Except One

Severity: High/Critical (breaks core free-earning mechanism)
Impact: Only one user can successfully call earnSnow per week, rendering the "free Snow token" feature unusable for the majority of users and potentially allowing a single actor to monopolize all free mints.
Affected Contract: Snow.sol


Summary

The earnSnow() function is designed to allow any user to mint one Snow token for free once per week. However, the cooldown is enforced by a single global variable s_earnTimer shared across all users. Once any user calls earnSnow (or buySnow, which also updates the timer), no other user can call earnSnow for a full week. This effectively disables the free earning feature for everyone except the first caller each week, breaking the protocol’s intended distribution model.


Vulnerability Details

The relevant code in Snow.sol:

uint256 private s_earnTimer; // global, not per-user
function earnSnow() external canFarmSnow {
if (s_earnTimer != 0 && block.timestamp < (s_earnTimer + 1 weeks)) {
revert S__Timer();
}
_mint(msg.sender, 1);
s_earnTimer = block.timestamp;
}
  • s_earnTimer is a single storage slot shared by all addresses.

  • The condition block.timestamp < (s_earnTimer + 1 weeks) prevents any call until one week after the last recorded timestamp, regardless of who made that previous call.

  • There is no per-user tracking of when an individual last claimed. Consequently, only the very first caller after the cooldown expires can mint a free token; all subsequent callers in the same week will be reverted.

This is also triggered by buySnow, which also updates s_earnTimer:

function buySnow(uint256 amount) external payable canFarmSnow {
// ... minting logic ...
s_earnTimer = block.timestamp;
}

So even a purchase resets the global cooldown, further limiting earnSnow.


Proof of Concept

The following Foundry test demonstrates that a second user cannot claim their free token within the same week.

// SPDX-License-Identifier: MIT
pragma solidity ^0.8.24;
import "forge-std/Test.sol";
import "../src/Snow.sol";
contract GlobalEarnTimerPoC is Test {
Snow snow;
address user1 = address(0x1);
address user2 = address(0x2);
function setUp() public {
// Deploy Snow with dummy parameters (WETH, fee, collector)
snow = new Snow(address(0xdead), 1, address(this));
// Advance past deployment time
vm.warp(block.timestamp + 1);
}
function test_GlobalCooldownBlocksOthers() public {
// User1 earns free Snow
vm.prank(user1);
snow.earnSnow();
assertEq(snow.balanceOf(user1), 1);
// User2 tries to earn immediately after
vm.prank(user2);
vm.expectRevert(Snow.S__Timer.selector);
snow.earnSnow();
// Advance time by 6 days (still within cooldown)
vm.warp(block.timestamp + 6 days);
vm.prank(user2);
vm.expectRevert(Snow.S__Timer.selector);
snow.earnSnow();
// After exactly 1 week, user2 can finally earn
vm.warp(block.timestamp + 1 weeks);
vm.prank(user2);
snow.earnSnow();
assertEq(snow.balanceOf(user2), 1);
}
}

Running this test shows that only one user per week can obtain a free token, confirming the global cooldown flaw.


Impact

  • Severe restriction of free token distribution: The protocol advertises that Snow tokens can be earned for free once a week, implying per‑user entitlement. In reality, only one global mint is allowed per week.

  • Monopolization by bots: A single bot can claim every free token by calling earnSnow immediately after each cooldown period, preventing all other users from ever receiving free tokens.

  • Broken incentive model: The free earning mechanism is meant to attract a wide user base. Its practical inoperability undermines the project’s value proposition.


Recommended Mitigation

Replace the global timer with a per‑user mapping that tracks the last claim timestamp for each address:

mapping(address => uint256) private s_lastEarnTimestamp;
function earnSnow() external canFarmSnow {
if (s_lastEarnTimestamp[msg.sender] != 0 &&
block.timestamp < (s_lastEarnTimestamp[msg.sender] + 1 weeks)) {
revert S__Timer();
}
_mint(msg.sender, 1);
s_lastEarnTimestamp[msg.sender] = block.timestamp;
}

Additionally, ensure that buySnow does not interfere with the per‑user earn cooldown (it should probably not update any earn timer, or update only for that user if desired). This change restores the intended once‑per‑week‑per‑user behavior.

Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge 9 days ago
Submission Judgement Published
Validated
Assigned finding tags:

[L-02] Global Timer Reset in Snow::buySnow Denies Free Claims for All Users

## Description: The `Snow::buySnow` function contains a critical flaw where it resets a global timer `(s_earnTimer)` to the current block timestamp on every invocation. This timer controls eligibility for free token claims via `Snow::earnSnow()`, which requires 1 week to pass since the last timer reset. As a result: Any token purchase `(via buySnow)` blocks all free claims for all users for 7 days Malicious actors can permanently suppress free claims with micro-transactions Contradicts protocol documentation promising **"free weekly claims per user"** ## Impact: * **Complete Denial-of-Service:** Free claim mechanism becomes unusable * **Broken Protocol Incentives:** Undermines core user acquisition strategy * **Economic Damage:** Eliminates promised free distribution channel * **Reputation Harm:** Users perceive protocol as dishonest ```solidity function buySnow(uint256 amount) external payable canFarmSnow { if (msg.value == (s_buyFee * amount)) { _mint(msg.sender, amount); } else { i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount)); _mint(msg.sender, amount); } @> s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` ## Risk **Likelihood**: • Triggered by normal protocol usage (any purchase) • Requires only one transaction every 7 days to maintain blockage • Incentivized attack (low-cost disruption) **Impact**: • Permanent suppression of core protocol feature • Loss of user trust and adoption • Violates documented tokenomics ## Proof of Concept **Attack Scenario:** Permanent Free Claim Suppression * Attacker calls **buySnow(1)** with minimum payment * **s\_earnTimer** sets to current timestamp (T0) * All **earnSnow()** calls revert for **next 7 days** * On day 6, attacker repeats **buySnow(1)** * New timer reset (T1 = T0+6 days) * Free claims blocked until **T1+7 days (total 13 days)** * Repeat step **4 every 6 days → permanent blockage** **Test Case:** ```solidity // Day 0: Deploy contract snow = new Snow(...); // s_earnTimer = 0 // UserA claims successfully snow.earnSnow(); // Success (first claim always allowed) // Day 1: UserB buys 1 token snow.buySnow(1); // Resets global timer to day 1 // Day 2: UserA attempts claim snow.earnSnow(); // Reverts! Requires day 1+7 = day 8 // Day 7: UserC buys 1 token (day 7 < day 1+7) snow.buySnow(1); // Resets timer to day 7 // Day 8: UserA retries snow.earnSnow(); // Still reverts! Now requires day 7+7 = day 14 ``` ## Recommended Mitigation **Step 1:** Remove Global Timer Reset from `buySnow` ```diff function buySnow(uint256 amount) external payable canFarmSnow { // ... existing payment logic ... - s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` **Step 2:** Implement Per-User Timer in `earnSnow` ```solidity // Add new state variable mapping(address => uint256) private s_lastClaimTime; function earnSnow() external canFarmSnow { // Check per-user timer instead of global if (s_lastClaimTime[msg.sender] != 0 && block.timestamp < s_lastClaimTime[msg.sender] + 1 weeks ) { revert S__Timer(); } _mint(msg.sender, 1); s_lastClaimTime[msg.sender] = block.timestamp; // Update user-specific timer emit SnowEarned(msg.sender, 1); // Add missing event } ``` **Step 3:** Initialize First Claim (Constructor) ```solidity constructor(...) { // Initialize with current timestamp to prevent immediate claims s_lastClaimTime[address(0)] = block.timestamp; } ```

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!