Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
Beatland Festival
Submissions
AI First Flight
Beatland Festival
AI First Flight #4
Beginner Friendly
Foundry
Solidity
NFT
EXP
AI First Flight
EXP
Mar 12th, 2026 → Mar 12th, 2026
View repo
View results
8 / 8
Submissions
Severity
Validity
Tags
Author
#1
The configurePass function resets the pass supply to zero, allowing the maximum supply limit to be bypassed.
Medium
Valid
[M-01] [H-1] Reseting the c...
plarochkin
#2
A reentrancy vulnerability in buyPass allows users to bypass the maximum supply limit.
Medium
Valid
[M-02] Function `FestivalPa...
plarochkin
#3
Passes can be transferred between addresses to repeatedly claim performance rewards.
High
Valid
[H-01] Pass Lending Reward ...
plarochkin
#4
An off-by-one error in redeemMemorabilia prevents the last item of a collection from being minted.
Medium
Valid
[M-03] Off-by-One in `redee...
plarochkin
#5
Unbounded nested loops in getUserMemorabiliaDetailed can lead to a Denial of Service (DoS).
Medium
Invalid
plarochkin
#6
The withdraw function uses transfer to send ETH, which can cause a Denial of Service.
Low
Invalid
plarochkin
#7
The setFestivalContract function lacks a zero-address check and prevents future upgrades.
Low
Invalid
plarochkin
#8
Single-step ownership transition for the organizer role.
Low
Invalid
plarochkin
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!