Snowman Merkle Airdrop

AI First Flight #10
Beginner FriendlyFoundrySolidityNFT
EXP
View results
Submission Details
Severity: low
Valid

Global s_earnTimer Allows DoS of Free Earnings and Blocks All Users' Weekly Claims

Root + Impact

Description

The earnSnow() function is intended to allow each user to claim free snow once per week, gated by a per-user timer. However, s_earnTimer is declared as a single uint256 rather than a mapping(address => uint256), meaning all users share one global timestamp.

Because the timer is global, any call to buySnow() (or earnSnow()) overwrites the shared timestamp, resetting the weekly window for every other user. An attacker can repeatedly call buySnow() to keep the timer perpetually fresh, permanently preventing all other users from successfully calling earnSnow().

// Root cause: single global variable instead of per-user mapping
uint256 private s_earnTimer; // should be mapping(address => uint256)
function earnSnow() external {
require(block.timestamp >= s_earnTimer + 1 weeks, "too early");
s_earnTimer = block.timestamp; // resets for ALL users
// ...
}
function buySnow() external payable {
s_earnTimer = block.timestamp; // resets the shared timer for everyone
// ...
}

Risk

Likelihood:

  • A single attacker can spam buySnow() in a tight loop (each call is cheap if it only requires a small payment or no payment), keeping s_earnTimer perpetually at block.timestamp and making block.timestamp >= s_earnTimer + 1 weeks unsatisfiable for everyone else.

  • Any user calling buySnow() at any point resets the global timer, immediately invalidating the weekly window for all other users who have not yet claimed.

Impact:

  • All users except the attacker are permanently denied access to the free earnSnow() function (indefinite DoS).

  • Users who were mid-window (e.g., claimed 2 days ago and expected 5 more days) have their remaining window erased by a single buySnow() call from any other address

Proof of Concept

dosEarnSnow() demonstrates that a single buySnow() call resets the shared s_earnTimer to block.timestamp. Immediately after, victimTriesToClaim() shows that any other user's earnSnow() reverts because the one-week window has just been restarted by the attacker. Repeating dosEarnSnow() in a loop makes the DoS permanent.

+ contract PoC {
+ Snow private snow;
+
+ constructor(address target) {
+ snow = Snow(target);
+ }
+
+ // Single call is enough to reset the global timer for all users
+ function dosEarnSnow() external payable {
+ snow.buySnow{value: 1 ether}();
+ // s_earnTimer is now block.timestamp
+ // No other user can satisfy: block.timestamp >= s_earnTimer + 1 weeks
+ }
+
+ // Victim attempts to claim immediately after
+ function victimTriesToClaim() external {
+ snow.earnSnow(); // reverts: "too early"
+ }
+ }

Recommended Mitigation

By converting s_earnTimer to a per-user mapping, each address gets its own independent weekly window. A user calling buySnow() only updates their own timestamp, leaving every other user's eligibility window untouched. This eliminates both the cross-user reset and the DoS vector entirely.

- uint256 private s_earnTimer;
+ mapping(address => uint256) private s_earnTimer;
function earnSnow() external {
- require(block.timestamp >= s_earnTimer + 1 weeks, "too early");
- s_earnTimer = block.timestamp;
+ require(block.timestamp >= s_earnTimer[msg.sender] + 1 weeks, "too early");
+ s_earnTimer[msg.sender] = block.timestamp;
// ...
}
function buySnow() external payable {
- s_earnTimer = block.timestamp;
+ s_earnTimer[msg.sender] = block.timestamp;
// ...
}
Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge about 3 hours ago
Submission Judgement Published
Validated
Assigned finding tags:

[L-02] Global Timer Reset in Snow::buySnow Denies Free Claims for All Users

## Description: The `Snow::buySnow` function contains a critical flaw where it resets a global timer `(s_earnTimer)` to the current block timestamp on every invocation. This timer controls eligibility for free token claims via `Snow::earnSnow()`, which requires 1 week to pass since the last timer reset. As a result: Any token purchase `(via buySnow)` blocks all free claims for all users for 7 days Malicious actors can permanently suppress free claims with micro-transactions Contradicts protocol documentation promising **"free weekly claims per user"** ## Impact: * **Complete Denial-of-Service:** Free claim mechanism becomes unusable * **Broken Protocol Incentives:** Undermines core user acquisition strategy * **Economic Damage:** Eliminates promised free distribution channel * **Reputation Harm:** Users perceive protocol as dishonest ```solidity function buySnow(uint256 amount) external payable canFarmSnow { if (msg.value == (s_buyFee * amount)) { _mint(msg.sender, amount); } else { i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount)); _mint(msg.sender, amount); } @> s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` ## Risk **Likelihood**: • Triggered by normal protocol usage (any purchase) • Requires only one transaction every 7 days to maintain blockage • Incentivized attack (low-cost disruption) **Impact**: • Permanent suppression of core protocol feature • Loss of user trust and adoption • Violates documented tokenomics ## Proof of Concept **Attack Scenario:** Permanent Free Claim Suppression * Attacker calls **buySnow(1)** with minimum payment * **s\_earnTimer** sets to current timestamp (T0) * All **earnSnow()** calls revert for **next 7 days** * On day 6, attacker repeats **buySnow(1)** * New timer reset (T1 = T0+6 days) * Free claims blocked until **T1+7 days (total 13 days)** * Repeat step **4 every 6 days → permanent blockage** **Test Case:** ```solidity // Day 0: Deploy contract snow = new Snow(...); // s_earnTimer = 0 // UserA claims successfully snow.earnSnow(); // Success (first claim always allowed) // Day 1: UserB buys 1 token snow.buySnow(1); // Resets global timer to day 1 // Day 2: UserA attempts claim snow.earnSnow(); // Reverts! Requires day 1+7 = day 8 // Day 7: UserC buys 1 token (day 7 < day 1+7) snow.buySnow(1); // Resets timer to day 7 // Day 8: UserA retries snow.earnSnow(); // Still reverts! Now requires day 7+7 = day 14 ``` ## Recommended Mitigation **Step 1:** Remove Global Timer Reset from `buySnow` ```diff function buySnow(uint256 amount) external payable canFarmSnow { // ... existing payment logic ... - s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` **Step 2:** Implement Per-User Timer in `earnSnow` ```solidity // Add new state variable mapping(address => uint256) private s_lastClaimTime; function earnSnow() external canFarmSnow { // Check per-user timer instead of global if (s_lastClaimTime[msg.sender] != 0 && block.timestamp < s_lastClaimTime[msg.sender] + 1 weeks ) { revert S__Timer(); } _mint(msg.sender, 1); s_lastClaimTime[msg.sender] = block.timestamp; // Update user-specific timer emit SnowEarned(msg.sender, 1); // Add missing event } ``` **Step 3:** Initialize First Claim (Constructor) ```solidity constructor(...) { // Initialize with current timestamp to prevent immediate claims s_lastClaimTime[address(0)] = block.timestamp; } ```

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!