Skip to content

[Status Network Contracts] Griefer can block KarmaAirdrop claim #97

@0x-r4bbit

Description

@0x-r4bbit

Context: https://github.com/Cyfrin/audit-2025-12-statusl2/issues/20

TLDR:

  • Attacker front-runs claim() with delegateBySig() called, consuming nonce
  • claim() of victim reverts because nonce is already used
  • Repeat

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions