
ECDSA signature-based token distribution contract with upgradeable architecture.
Contract upgrade authority incorrectly assigned to project owner instead of deployer.
User-provided claim data in hook calls is not part of the signed payload.
Contract version not included in signatures, allowing replay across upgrades.
Get a free 30-minute security assessment. We will review your codebase scope and flag the top 3 risk areas.
No commitment required. Typical audits start within 1–2 weeks.