The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, it allows malicious users to always win and get rewards.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
all-for-one all for one - |