Snow.sol uses a single contract-wide s_earnTimer variable to enforce the one-week cooldown for earnSnow(). This means the cooldown is shared by every user, not tracked per account.
Because buySnow() also updates s_earnTimer = block.timestamp, any purchase resets the cooldown for the entire protocol. Similarly, any successful earnSnow() call also resets the cooldown for everyone else.
As a result, during active buying, or after any user earns Snow, all other users are prevented from calling earnSnow() for one week. If buySnow() is called repeatedly within each one-week window, earnSnow() can be effectively disabled for the whole farming period.
The cooldown state is global:
Both buySnow() and earnSnow() write to this same variable:
The check should be based on the caller’s own last earn time, e.g. mapping(address => uint256), not a single shared timestamp.
Likelihood:
Any normal buySnow() or earnSnow() call triggers the issue. It does not require a special state or advanced exploit. During an active farming period, buys are expected, so the problem is likely to occur naturally.
Impact:
After any user calls earnSnow(), every other user must wait one week before they can earn Snow.
After any user calls buySnow(), every other user must wait one week before they can earn Snow.
During active buying, s_earnTimer is continually refreshed, so earnSnow() can remain unavailable for the entire farming duration.
An attacker or active buyer can repeatedly call buySnow(1) every week to keep the global timer fresh and prevent other users from earning free Snow.
The free weekly Snow distribution mechanism is broken, and only buying users can reliably obtain Snow tokens.
This is a denial-of-service issue against the intended earnSnow() functionality. It does not directly steal funds, but it breaks a core protocol feature.
The following Foundry tests demonstrate that one user’s earnSnow() call blocks another user, and that buySnow() also blocks earnSnow() for everyone.
Track the earn cooldown per user instead of globally.
## Description: The `Snow::buySnow` function contains a critical flaw where it resets a global timer `(s_earnTimer)` to the current block timestamp on every invocation. This timer controls eligibility for free token claims via `Snow::earnSnow()`, which requires 1 week to pass since the last timer reset. As a result: Any token purchase `(via buySnow)` blocks all free claims for all users for 7 days Malicious actors can permanently suppress free claims with micro-transactions Contradicts protocol documentation promising **"free weekly claims per user"** ## Impact: * **Complete Denial-of-Service:** Free claim mechanism becomes unusable * **Broken Protocol Incentives:** Undermines core user acquisition strategy * **Economic Damage:** Eliminates promised free distribution channel * **Reputation Harm:** Users perceive protocol as dishonest ```solidity function buySnow(uint256 amount) external payable canFarmSnow { if (msg.value == (s_buyFee * amount)) { _mint(msg.sender, amount); } else { i_weth.safeTransferFrom(msg.sender, address(this), (s_buyFee * amount)); _mint(msg.sender, amount); } @> s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` ## Risk **Likelihood**: • Triggered by normal protocol usage (any purchase) • Requires only one transaction every 7 days to maintain blockage • Incentivized attack (low-cost disruption) **Impact**: • Permanent suppression of core protocol feature • Loss of user trust and adoption • Violates documented tokenomics ## Proof of Concept **Attack Scenario:** Permanent Free Claim Suppression * Attacker calls **buySnow(1)** with minimum payment * **s\_earnTimer** sets to current timestamp (T0) * All **earnSnow()** calls revert for **next 7 days** * On day 6, attacker repeats **buySnow(1)** * New timer reset (T1 = T0+6 days) * Free claims blocked until **T1+7 days (total 13 days)** * Repeat step **4 every 6 days → permanent blockage** **Test Case:** ```solidity // Day 0: Deploy contract snow = new Snow(...); // s_earnTimer = 0 // UserA claims successfully snow.earnSnow(); // Success (first claim always allowed) // Day 1: UserB buys 1 token snow.buySnow(1); // Resets global timer to day 1 // Day 2: UserA attempts claim snow.earnSnow(); // Reverts! Requires day 1+7 = day 8 // Day 7: UserC buys 1 token (day 7 < day 1+7) snow.buySnow(1); // Resets timer to day 7 // Day 8: UserA retries snow.earnSnow(); // Still reverts! Now requires day 7+7 = day 14 ``` ## Recommended Mitigation **Step 1:** Remove Global Timer Reset from `buySnow` ```diff function buySnow(uint256 amount) external payable canFarmSnow { // ... existing payment logic ... - s_earnTimer = block.timestamp; emit SnowBought(msg.sender, amount); } ``` **Step 2:** Implement Per-User Timer in `earnSnow` ```solidity // Add new state variable mapping(address => uint256) private s_lastClaimTime; function earnSnow() external canFarmSnow { // Check per-user timer instead of global if (s_lastClaimTime[msg.sender] != 0 && block.timestamp < s_lastClaimTime[msg.sender] + 1 weeks ) { revert S__Timer(); } _mint(msg.sender, 1); s_lastClaimTime[msg.sender] = block.timestamp; // Update user-specific timer emit SnowEarned(msg.sender, 1); // Add missing event } ``` **Step 3:** Initialize First Claim (Constructor) ```solidity constructor(...) { // Initialize with current timestamp to prevent immediate claims s_lastClaimTime[address(0)] = block.timestamp; } ```
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.