BeatToken has no supply cap, and the organizer can set any reward in createPerformance. A single check-in mints reward * multiplier to the attendee with no protocol-level limit.
Normal behavior: attendees earn BEAT proportional to a performance’s configured baseReward and their pass tier multiplier.
createPerformance accepts arbitrary reward with no maximum. attendPerformance mints baseReward * multiplier directly via BeatToken.mint, diluting all holders and devaluing memorabilia priced in BEAT.
Likelihood:
A compromised or careless organizer sets an extremely large reward for a performance.
Combined with H-1, pass rotation multiplies the already huge mint across many addresses.
Impact:
Total BEAT supply can jump by millions per transaction.
Memorabilia redemption costs (priceInBeat) become meaningless.
Economic design of “earn at shows, spend on merch” collapses.
And/or inherit ERC20Capped on BeatToken and enforce a global max supply.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.