Platform: Code4rena
Start Date: 24/02/2022
Pot Size: $75,000 USDC
Total HM: 21
Participants: 28
Period: 7 days
Judge: alcueca
Total Solo HM: 15
Id: 94
League: ETH
Rank: 17/28
Findings: 1
Award: $657.38
🌟 Selected for report: 0
🚀 Solo Findings: 0
🌟 Selected for report: thankthedark
Also found by: Afanasyevich, cmichel
As the current private sales implementation makes no use of nonces, it makes possible the following example scenario:
buyFromPrivateSaleFor()
function(As mappings are not correctly deleted Bob will not be able to put a new buy price after rebuying it from Alice. See my other submitted issues. But this is an issue that will be present once the problems with deleting the mappings are addressed)
N/A
A nonce linked to the buyer should be included in the signature that is increased every time a signature is used.
#0 - HardlyDifficult
2022-03-02T16:28:48Z
#1 - alcueca
2022-03-14T11:33:25Z
Agree with the severity rating in #68