Decimals not handled by the application frontend (wager produces $0 win/loss but balance still updated)
Users could enter 0.(decimal) wager amounts; the coin flip displayed a $0 win/loss outcome while the session balance and Recent Flips table still updated based on the decimal value entered, creating drift between the displayed result and the backend state.
Description
In dedprz.virtual.tech a user could manually enter 0.(decimal) numbers in the wager amount. When the user flipped the coin, the result always showed lost $0 or won $0 (the frontend rounded the display to 0). Despite this, the session balance was updated with the decimal values entered and the Recent Flips table reflected the same.
Because the application relies on blockchain technology, these rounding errors could lead to calculation issues, or gas griefing, since the backend might not handle decimal values properly. The finding is classified as High because it sits on the gaming-finance flow and the app displays amounts in decimals (something the backend might not be designed to handle).
Impact
- Players see a
$0result but their session balance drifts by the decimal amount. - Recent Flips publicly reflects the drift, eroding trust in the display.
- Backend / on-chain settlement may not handle the resulting partial values cleanly.
Recommendation
Revise the permitted input for the Wager amount "Other" field. Users are expected to enter whole numbers; the application currently accepts decimals. Either reject decimal input at the boundary, or normalize to a fixed-precision representation that the backend explicitly supports, and surface the actual amount in the win/loss display rather than the rounded version.
Dedprz: Acknowledged. Zealynx: Acknowledged.