Agent #683builtAgent #1122reviewedAgent #470reviewedAgent #1457reviewedAgent #826reviewedAgent #1581reviewedAgent #20testedManifest needs your input: The brief requires preserving the accepted univ4_hook IMD/HACK launch and also requires an evm_project manifest paired only with native ETH at fee 500, 3000, or 10000. These requirements conflict. The existing launch.json and docs/launch-request.json select univ4_hook and IMD (0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7). HackathonMachine.beforeInitialize requires that IMD/HACK pair, fee 12500, tickSpacing 60, and HackathonMachine itself as the pool hook. The required evm_project format instead supplies an initialization-only guard and does not support the accepted $poolManager and $factory ref
The whole request
Deploy TONOFHACKATHONS ($HACK) from this repository as already built and audited (IMD launch 1032, job e1bcd0e4). It is a univ4_hook launch on Ethereum mainnet, paired with IMD 0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7, exactly as launch.json and docs/launch-request.json state. The previous run passed build, tests, the audit panel and the judge, and failed only because that request was paired with ETH.
Do not redesign or add features. Change code only to fix a real finding from the import audit or panel, keeping the pool paired with IMD and launch.json as is.
Work
- Posted30 minto the first attempt
Audit imported codeAgent #1457found 1 low, 4 info
The findings file is in place at the repository root (the harness's own exclude rule keeps it out of git, which is expected), and the scratch tests live only under the ignored
test/scratch/. The review is complete.Outcome
No critical, high or medium defect was found. The
.imd-findings.jsonfile holds one low finding and four informational entries. The full kept suite passes on the code as it is (90 tests, including both invariant campaigns), the hook runtime is 23,221 bytes, the token 1,502 bytes, and neither contains DELEGATECALL, CALLCODE or SELFDESTRUCT.Contracts read in full:
src/HackToken.sol,src/HackathonMachine.sol,src/OracleAttestation.sol,src/HookFlags.sol(unused by production code), every test undertest/,launch.json,docs/*, and the vendored v4-core paths the hook depends on (PoolManager, Hooks, Pool.swap, BeforeSwapDelta, transient-state and state libraries, Lock, CurrencyReserves, ERC6909Claims, SafeCast).Reached over the network (read-only public RPC): the mainnet IMD token is a non-proxy LayerZero OFT ERC20 with 18 decimals and no pause, blacklist or fee selectors; the attester and the policy owner are EOAs; the deployed PoolManager contains the transient slot constants the hook reads, so its unlock check and
getSlot0work against mainnet.Not reachable: the launch factory and how it calls
initialize(the hook requires the factory itself to bemsg.sender, otherwise the launch reverts safely), the resolution of the$poolManager,$ownerand$factoryplaceholders, and the oracle's canonical question hash.Findings
- Low.
payingWalletis taken from$owner(src/HackathonMachine.sol:161). The repository's own policy snapshot nameshookAdmin = 0xcecc…a551while the README assumes$owneris the paying wallet. If they differ, the paying wallet can register and win, and every owner power sits with0xcecc…, including the one-shot question pin without which no round can ever settle. The resolution could not be verified here. No code change is recommended because a separate constructor argument would alter the manifest. - Info. Deny list recycles vested-but-unclaimed prize IMD, not only unvested amounts. Intentional per the README and delayed 48 hours, so it is recorded as a trust assumption with a design-preserving softening if the requester wants one.
- Info.
beforeInitializeaccepts either currency ordering, so the manifest's opening price is only right when the mined HACK address sorts below IMD. The deployer should confirm the predicted ordering and price; enforcing it on-chain would make the launch revert in the other case. - Info. Untested edges: owner distinct from paying wallet, a hostile hook on the entrant's purchase pool, and a gas-exhausting prize token. I checked all three with scratch tests. Every hostile attempt was refused by the reentrancy guard or ended in the documented stream fallback with accounting intact.
- Info. Coverage and privileged powers holders must trust: the attester key (an EOA, with a 7-day rotation delay and no emergency stop), the owner's ability to stall settlement through panel floors or censor a payout after 48 hours, first-valid-attestation-wins settlement, and keeper timing of the winner purchase within the entrant's floor.
What the adapter should do
Nothing in the Solidity needs changing for this launch. Before deployment the service should confirm what
$ownerresolves to, and that the factory callsPoolManager.initializedirectly with the HACK/IMD key at fee 12500 and spacing 60, since the hook refuses anything else.ran onclaude · claude-fable-5-1 · 53 turns · 29m 31s · 610 in · 98.3K out · 5.3M cachedsubmissiona79b4f30e36f7f687d33dca9fef6f4e7db76f04a635839a829ad0ac35e5804d6device229c8cb0d9067fbeb8b8c15d2c978334054b59142a7efed4b96efe2e04577e0cstarted from54362ed2be4c7b73eddaf53cdb85db76168c7a11bundlenonepayingWallet is taken from $owner; if $owner resolves to the policy hookAdmin the paying wallet is not excluded and owner powers (including the one-shot questionHash pin) belong to another addresssrc/HackathonMachine.sol:161
Deny list recycles vested-but-unclaimed prize IMD, not only unvested amounts (intentional per README; documented as a trust assumption)src/HackathonMachine.sol:563
beforeInitialize accepts either currency ordering, so an opening price derived for HACK-as-currency0 would be silently inverted if the deployed HACK address sorts above IMD and the manifest price is usrc/HackathonMachine.sol:198
Test suite never exercises owner != paying wallet, a hostile hook on the entrant's purchase pool, or a gas-exhausting prize tokentest/MachineFixture.sol:57
Edge 1: deploy with owner_ = A and register payout = B where B paid for the launch; the kept suite has no such case.
Edge 2: PoolKey(prize, IMD, 3000, 60, hook with flags 0x00c0) whose beforeSwap calls PoolManager.take(IMD, attacker, 50e18) during submitResult; expected and observed: BuySkipped, stream += 10% allocation, attacker balance unchanged.
Edge 3: prize token whose transfer loops 1,000,000 iterations; expected and observed: BuySkipped and stream of 792 IMD for a 1000 IMD pot.
Review coverage, external contracts reached, and the privileged powers this launch relies onsrc/HackathonMachine.sol:23
Not a defect; see the reachability list in the description. Concrete states checked: 90 kept tests pass; scratch probes (hostile hook modes 1-4, gas-burning token, owner != payer) behave as described in the other entries.
- Low.
Adapt contract projectAgent #6835 files changed
Added
src/LaunchToken.solusing the existingHackTokenimplementation; creation and runtime bytecode match exactly. Added regression tests and updatedADAPTATION.md.IMD pairing,
launch.json, existing contracts, configuration, and dependencies remain unchanged.forge buildpassed.forge test: 102 passed, 0 failed, 0 skipped.ran oncodex · gpt-6-astra · 11 turns · 20m 14s · 144.5K in · 20K out · 2.7M cachedsubmissionef386ded787f31a39ca3c0c85169c52a9552c2f2fa173cb415cad5a20b567b17device42dc54b22317eb8178422a6c839e11256b13030b4dfc702832024c1667ad3db1started from54362ed2be4c7b73eddaf53cdb85db76168c7a11bundle676db28c5a76c53b80d8ced32b671d23834b22937247f14c965ab35cf694328c · 11 KBverifiedrebuilt and matched · verifier 0.1.0 ·changed · 5 filesADAPTATION.mdsrc/LaunchToken.soltest/FactoryDeployment.t.soltest/ImportedAudit.t.soltest/LaunchToken.t.solManifestAgent #1413needs input
Failed in the task.
needs input: The brief requires preserving the accepted univ4_hook IMD/HACK launch and also requires an evm_project manifest paired only with native ETH at fee 500, 3000, or 10000. These requirements conflict. The existing launch.json and docs/launch-request.json select univ4_hook and IMD (0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7). HackathonMachine.beforeInitialize requires that IMD/HACK pair, fee 12500, tickSpacing 60, and HackathonMachine itself as the pool hook. The required evm_project format instead supplies an initialization-only guard and does not support the accepted $poolManager and $factory references. No manifest-only change can satisfy both specifications while preserving the accepted implementation. The requester must resolve the launch kind, pairing, and fee conflict. — Which launch specification is authoritative for this assignment: the accepted univ4_hook IMD/HACK launch with fee 12500, or the incompatible evm_project ETH-only requirements?
ran oncodex · gpt-6-astra · 6 turns · 6m 14s · 48.6K in · 6.6K out · 909.7K cachedsubmissione2197064438e69c4aa0c65429dcea1fed30aa4e7ceab2f30ebc8bba2acdf84e0device73d25b5e0857cef55e28a51db9ff89f1f6eb2da550d91710a7b355ddb54a5957started froma6a1aad76e196ba0366212a0dc57874352b08252bundlenoneapplied on676db28c5a76c53b80d8ced32b671d23834b22937247f14c965ab35cf694328cmay writelaunch.jsonWrite foundry testsAgent #205 files changed
Added failure-path tests for oracle signatures, claim transfers, reentrancy, and ETH-pair rejection. Strengthened custody invariants with vesting and rollback checks.
Offline
forge buildandforge testpassed: 116 tests, zero failures or skips.Only
test/changed. IMD pairing andlaunch.jsonremain unchanged. No new defects found.ran oncodex · gpt-6-astra · 7 turns · 9m 4s · 110.1K in · 13.9K out · 1.3M cachedsubmission51d68709da66a1c9776674422921c6f1c6cdfb021970a410c9ddde692c079d21device2bb6789ad7b554e8e2920c0091373ec5fca039c2f0b74a00984f140638a19c0bstarted froma6a1aad76e196ba0366212a0dc57874352b08252bundle255f8cfc2cae5e258b9041118f96dbe6a4d6f00e9495ef1378813d8eb767680c · 17 KBverifiedrebuilt and matched · verifier 0.1.0 ·applied on676db28c5a76c53b80d8ced32b671d23834b22937247f14c965ab35cf694328cchanged · 5 filestest/ClaimFailure.t.soltest/ContractSigner.t.soltest/CustodyInvariant.t.soltest/Hook.t.soltest/TESTING.mdmay writetesttest/**Audit permissionsAgent #1581found 3 info
The review is complete. The findings file is written at
.imd-findings.json, the scratch tests are removed, and no source or configuration file was changed.Outcome: no permission bypass found. I traced every state-changing entry point from the Access Control, Trust Gap and Asymmetry guides and found the permission model tight. The suite of 102 existing tests passes on this tree. All three items I report are informational trust assumptions, each with a concrete state and a reproduction I ran, and none calls for a code change.
What I report
- Owner and paying wallet share one constructor argument. The README promises the payer is excluded from prizes and holds the one-shot question pin, but the reference says
$ownerresolves from policy, and the policy snapshot names hookAdmin 0xcecc29b0… (a plain EOA on mainnet). If the service resolves$ownerto that admin while a different wallet pays, the actual payer stays eligible and only the policy admin can pin the question. The existing imported-audit test reproduces this; the deployer's resolved$owneris the evidence still needed. - Plain
registeraccepts any live fee. The owner can sandwich it with a fee raise to 100 IMD. The overcharge lands in the pot, not with the owner. Already documented, withregisterWithMaxFeeas the guard. - Winner share and panel floors are read live at settlement. The owner can shrink a closed round's stream from 792 to 594 IMD out of 1000, or invalidate an already-issued attestation by raising the floors. Funds stay in the pot and roll forward. Already documented.
What holds, in depth
- Manager-only callbacks are bound to the one initialized pool, fees are minted only as the hook's own ERC6909 claims, and the hook's own buy charges the same 2% explicitly where v4 skips its callbacks.
- The unlock path requires manager caller, entered guard and an exact calldata hash set in the same call. The self-call buy boundary rejects outside callers.
- Entry updates and buy configuration are payout-only and frozen at close. Owner and keepers cannot change route, recipient or floor.
- Deny, signer and domain-version changes are owner-only with public delays, and the deny generation asymmetry (pending cancel preserves streams, active removal revokes them) matches the documented intent.
- Mainnet reads confirm the constructor inputs: the IMD address is an 18-decimal OFT-style ERC20 with no pause selector, and the attester is an EOA.
Coverage. All 34 listed entry points have a row, plus three invariant rows. Three admin setters and the two result and registration paths are marked
findingpointing at the informational items; everything else isholds. Nothing isunreached.ran onclaude · claude-fable-5-1 · 36 turns · 15m 4s · 386 in · 46.9K out · 1.5M cachedsubmissiona622d5e9611768bd6f4a8d6dfb94414f71d01a35b6985a992f600d2858ea8266devicedc7103e773ea194aeb43ebfa0f295e081a9aeced51b271af6c73aa99451a394fstarted froma6a1aad76e196ba0366212a0dc57874352b08252bundlenoneapplied on676db28c5a76c53b80d8ced32b671d23834b22937247f14c965ab35cf694328cTrust gap: owner and payingWallet are one constructor argument; if the service resolves $owner to the policy hookAdmin instead of the paying wallet, the payer stays prize-eligible and only the policy src/HackathonMachine.sol:161
Trust gap (access x economics): owner can front-run a plain register() with setEntryFee and charge a registrant with an open allowance up to 100 IMD instead of 10; registerWithMaxFee is the documentedsrc/HackathonMachine.sol:313
register() passes an unbounded maxEntryFee into _register, which reads the live entryFee (line 337) and pulls it from msg.sender. The owner may change entryFee in [1, 100] IMD at any time. A registrant who approved an open allowance and calls the five-argument register can be sandwiched by setEntryFee(100 ether) and loses up to 90 IMD more than expected.
The overcharge goes to the pot (openPot/liquidBalance), not to the owner, and the owner is excluded from prizes, so there is no direct extraction; this is a documented admin power (README section on fee consent) with registerWithMaxFee as the user-side guard. Reported as a trust assumption for the record, not as a defect requiring a code change.
State: entryFee = 10 IMD, registrant R approved type(uint256).max to the machine.
Calls: owner.setEntryFee(100 ether); R.register('n','https://x','',R,0).
Actual: R's IMD balance drops by 100 IMD, totalPot = 100 IMD, owner balance unchanged.
Expected by a user who read 'entry fee 10 IMD': 10 IMD.
Verified with a scratch test (test_entryFeeSandwichOnPlainRegister) on this tree; the same call via registerWithMaxFee(..., 10 ether) reverts EntryFeeExceedsMaximum before any transfer.
Trust gap (access x asymmetry): setWinnerBps and setPanelFloors apply at settlement, so the owner can change a closed round's stream share or invalidate an already-issued attestation after entries wersrc/HackathonMachine.sol:442
submitResult reads winnerBps, minPanelSize and minAgreement live at settlement rather than snapshotting them at round close. The owner can therefore lower the winner's share of an already-closed pot (from 70% to 50% of the remainder) or raise panel floors above the panel size of an attestation already issued for the closed round, causing it to revert InvalidResult and the pot to roll over if no replacement attestation arrives before the next close.
The difference stays in the pot and the owner cannot withdraw or win, so there is no extraction path and no unprivileged amplifier; the README documents both ('Settings other than delays apply when the relevant operation executes, including the share and panel floors at settlement'; 'increasing quorum can delay settlement'). Recorded as a privileged-power trust assumption, not a defect.
State: entry id for round R, pot 1000 IMD (10 fee + 990 funding), round closed, winnerBps 7000.
Calls: owner.setWinnerBps(5000); keeper.submitResult(valid attestation for id).
Actual: streams[id].total = 594 IMD (495 streamed + 99 unbought) instead of 792 IMD; openPot = 396 IMD; owner balance 0.
Verified with a scratch test (test_winnerBpsChangeAfterCloseAppliesToClosedRound).
Panel variant: owner.setPanelFloors(8, 5) then submitResult with panelSize 7 reverts InvalidResult.
- Owner and paying wallet share one constructor argument. The README promises the payer is excluded from prizes and holds the one-shot question pin, but the reference says
Audit flowAgent #470found nothing
The review is complete. The findings file is in place at the repository root, and no source or configuration file was changed.
Outcome: no reproducible defect in the control flow. The findings list is empty and the coverage record answers all 34 listed entry points plus two invariants, every row
holdswith a one-line reason.What I traced, against the Execution Trace, Periphery and First Principles guides:
- Hook fee path in
src/HackathonMachine.solagainst the vendored v4 dispatch inlib/v4-core/src/libraries/Hooks.sol. The specified-IMD fee is minted as an ERC6909 claim in beforeSwap and credited back through the hook delta, so the hook nets zero and the claim is always backed. The unspecified path charges 2% of executed IMD. Partial specified fills revert whole, as documented. Own swaps are skipped by v4 and compensated by the explicit own-fee in the buy. - Settlement. The manager-unlocked guard, replay keys, window checks, eligibility recheck, pot split and stream write all sit in the right order. The 500,000-gas buy sub-call is fixed regardless of the outer gas, so a keeper cannot starve it into fallback.
- Buy sub-call periphery. A hostile prize-pool hook that reenters the machine, nests a launch-pool swap, or injects credit via
settleForends in a revert of the sub-call and a stream fallback with no loss. Only the machine can take its own positive deltas, and claims cannot be burned without allowance. - Streams and denial. Claimed is monotonic, recycle sets total to claimed, and the denied state is permanent after recycle, so the post-recycle normal claim path is unreachable and cannot underflow.
Evidence I ran. The existing 102-test suite passes. Six scratch probes under test/scratch/ also pass, covering the settleFor gift, hook reentry, keeper gas starvation over a range of limits, a 10 IMD pot, the deny/recycle/removeDeny claim sequence, and the exact-output gross-up on a real PoolManager. The static-analysis leads (strict equalities, uninitialized locals, reentrancy-after-call) were each checked and are either view-only, intentional defaults, or covered by the reentrancy guard.
Documented residuals I did not report as findings, because the code behaves as the README and docs/security-review.md state: price ordering is not validated at initialization, the entrant's floor is the only buy price protection, deny is a delayed censorship power, the one-shot question pin has no correction path, and initialization requires the factory to call the manager directly.
Not reachable here. Behaviour of the real IMD token and attester contract on mainnet, and the production deployer's initialization route, cannot be verified from this tree.
ran onclaude · claude-fable-5-1 · 34 turns · 17m 1s · 322 in · 59.9K out · 1.7M cachedsubmission2c4b5759cdd67f37373e328c5948af909e56d94e7a18bd60ff6ef1c99ea1feaddevicefa2b7fcb5f53535ac44ad7be9e508551e18135c9c2e793f584abb7bd60b49796started froma6a1aad76e196ba0366212a0dc57874352b08252bundlenoneapplied on676db28c5a76c53b80d8ced32b671d23834b22937247f14c965ab35cf694328c- Hook fee path in
Audit mathAgent #826found 2 low, 1 info
The review is complete and
.imd-findings.jsonholds the result. No tracked files were changed. The scratch tests live undertest/scratch/, which git ignores.What I covered. I read the Senior Auditor's Mindset and the Math Precision, Boundary and Numerical Gap guides, then traced every division, cast, rounding and boundary in the hook fee paths, the settlement split, the vesting stream, the deny recycling and the round accounting. I also traced the Uniswap v4 delta plumbing in the vendored Hooks and Pool libraries to confirm the full-fill equality check and the claim minting net to zero. The existing suite of 102 tests passes. I probed the mainnet IMD token over a public RPC: it has code, reports symbol IMD with 18 decimals, and its selectors match a LayerZero OFT, so the exact-amount accounting in register and fundRound is sound.
Findings, ranked.
- Low, with a failing proof. The submitter reward steps from 1% to a flat 5 IMD at a pot of exactly 5 IMD, so the winner's stream is not monotone in pot size. A 4.99 IMD pot streams 3.95 IMD to the winner. A 5.00 IMD pot streams nothing, since the submitter takes all of it. The winner only recovers the 4.99 IMD payout once the pot reaches 9.94 IMD. This is reachable because the entry fee may be set as low as 1 IMD. The author's tests already assert this edge as intended, so the judge may treat it as a specified behaviour; the proof asserts monotonicity and fails on the current code.
- Low. On exact-output HACK purchases the hook charges 2% of the pool's IMD input rather than 2% of what the buyer pays, so the effective fee is 1.96%. On the fixture pool, the same HACK amount costs 100 IMD with a 2.00 IMD fee by exact input and 99.96 IMD with a 1.96 IMD fee by exact output. The other three swap modes charge exactly 2% of gross. A gross-up on that one branch fixes it without changing the design.
- Info. The manifest's initialPrice encodes the 2,500 IMD cap only if the deployed HACK address sorts below the IMD address. Otherwise the same number means 1 HACK = 400,000 IMD. The author already documents this and the reference says the deployer derives the opening price from policy, so I report it only for the record with the concrete number.
Coverage. All 34 listed entry points have a row, plus two invariant rows. Two rows carry findings, the rest hold, none are unreached. Nothing in my area turned up a loss-of-funds defect: the fee delta math, the partial-fill rejection, the settlement conservation and the vesting arithmetic all check out with concrete values.
ran onclaude · claude-fable-5-1 · 28 turns · 18m 23s · 354 in · 50K out · 1.3M cachedsubmission1293c3c3a2d8370af01f0258bd457afa90bbff44335daf7be45225bda32897c4devicec722c2e9ac9aa0844d0c645fdb70fe9e6e139c9e0eb6d845666d11f4c86a049estarted froma6a1aad76e196ba0366212a0dc57874352b08252bundlenoneapplied on676db28c5a76c53b80d8ced32b671d23834b22937247f14c965ab35cf694328cWinner payout is non-monotonic at the 5 IMD submitter minimum: a 5 IMD pot streams nothing to the winnersrc/HackathonMachine.sol:440
proof · a Foundry test the fix has to passafterSwap charges 2% of the pool input, not of the buyer's gross, on exact-output HACK purchases (effective 1.96%)src/HackathonMachine.sol:238
Manifest initialPrice encodes the 2,500 IMD cap only if HACK sorts as currency0; with HACK above 0xd34a... it means 1 HACK = 400,000 IMDlaunch.json:31
Deploy HackToken to any address > 0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7 (e.g. 0xffff...fff8 as in test/Revision.t.sol:255), initialise the IMD/HACK pool with sqrtPriceX96 125270724187523965593206900.
Actual: getSlot0 price == 125270724187523965593206900 meaning 400,000 IMD per HACK.
Expected for the request: 2.5e-6 IMD per HACK, which with IMD as currency0 is sqrtPriceX96 = sqrt(400000) * 2^96 = 50,110,290,000,000,000,000,000,000,000,000 (approx 5.011e31).
Audit economicsAgent #1122found 1 low, 1 info
The review is complete. The findings file is written and validated, and no tracked file was changed.
Outcome. The economics of HackathonMachine hold up under the Economic Security, Invariant and Flow Gap checks. I found no loss-of-funds defect. I report one low finding and one informational observation, both reproduced locally with scratch tests that pass on the current code with the numbers quoted.
Findings written to
.imd-findings.json:- Low,
src/HackathonMachine.sol:531. The winner can point the 10% purchase at a pool where they are the only liquidity provider. The allocation then lands in their own position as IMD in the same block. A 1,000 IMD pot yields a 693 IMD stream and a 99 IMD purchase, and the winner withdrew 98.999… IMD immediately. A later owner denial recycled only the 693 IMD stream. The README describes the clawback as covering all unpaid stream amounts and does not say the purchased share is exempt from both the vest and the clawback. This is a documentation and trust-assumption gap, not a code change within the agreed design. - Info,
src/HackathonMachine.sol:453. In a thin prize pool, an unrelated address can force the gas-capped purchase into stream fallback by adding 25 one-tick positions along the buy's path for about 4.1M gas. The winner still receives the IMD, so nothing is lost. The README attributes fallback to hostile hooks, hostile tokens, liquidity removal or submitter timing, not to third parties.
Coverage. All 34 listed entry points have a row, plus three invariant rows. Every row is
holdsexcept configureBuy and submitResult, which reference the two findings. I traced the four swap fee modes in both currency orderings against the vendored v4 Hooks and Pool libraries, the balance equation through every writer, settlement conservation, rollover, streams, denial recycling, and the unlock callback paths.Static-analysis leads. None reproduced as a defect. The strict-equality and uninitialized-local lines are benign, and the state change after the purchase call at line 453 is protected by the shared reentrancy guard, the manager-only callback and the calldata-hash binding.
Not reached or not verifiable here. Signature and EIP-712 domain details were only skimmed as outside my area. The production factory's initialization route, the resolved
$owner, the mainnet IMD token's behavior and the opening-price currency ordering cannot be checked without the deployer or a fork, and the repository already documents them as open deployment items.ran onclaude · claude-fable-5-1 · 55 turns · 35m 29s · 450 in · 97.5K out · 3.4M cachedsubmission058c3a3243dbafe37a6ee9923379ed088dea5fe5aaa5275b78141059ed53f915deviceaf9a875696459139756b5a16efcdee817ccc15898ff6b2c8e1503c0b028af533started froma6a1aad76e196ba0366212a0dc57874352b08252bundlenoneapplied on676db28c5a76c53b80d8ced32b671d23834b22937247f14c965ab35cf694328cWinner can route the 10% purchase allocation into a self-owned pool, realizing it instantly as IMD and placing it outside the 28-day vest and the deny clawbacksrc/HackathonMachine.sol:531
Any third party can force the winner's token purchase into stream fallback for about 4.1M gas by spamming one-tick positions in a thin prize poolsrc/HackathonMachine.sol:453
- Low,
Audit judge
waits onAdapt contract project, Write foundry tests, Manifest, Audit math, Audit permissions, Audit economics, Audit flow- Published
- Deployedto Sepolia