Art Gobblers contest - throttle's results

Experimental Decentralized Art Factory By Justin Roiland and Paradigm.

General Information

Platform: Code4rena

Start Date: 20/09/2022

Pot Size: $100,000 USDC

Total HM: 4

Participants: 109

Period: 7 days

Judge: GalloDaSballo

Id: 163

League: ETH

Art Gobblers

Findings Distribution

Researcher Performance

Rank: 56/109

Findings: 1

Award: $55.20

🌟 Selected for report: 0

πŸš€ Solo Findings: 0

Lines of code

https://github.com/code-423n4/2022-09-artgobblers/blob/main/src/ArtGobblers.sol#L560-L567

Vulnerability details

Impact

Reveal feature halted. Unfair disadvantage for holders with unrevealed Gobblers

Proof of Concept

https://github.com/code-423n4/2022-09-artgobblers/blob/main/src/ArtGobblers.sol#L560-L567

When setting new oracle there is no validation if the new address is address(0) or a smart contract

The severity here is that an orcale randomness feed might be temporarily halt and with that the reveal feature is halted. And this is detrimental to the unrevealed Gobbler holders because they are late in Goo emissions which means they lose purchasing power.

Tools Used

Manual review

Validate oracle address

#0 - Shungy

2022-09-28T13:37:25Z

It can be upgraded again to a proper address.

#1 - GalloDaSballo

2022-10-09T16:35:47Z

Address(0) -> Low

#2 - GalloDaSballo

2022-10-09T16:35:49Z

L

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax Β© 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter