Lack of input validation in deposit function triggers zero-value transactions
The deposit amount field was not properly sanitized. Users could submit empty values or special characters; the Approve button still produced a zero-value transaction that consumed gas without transferring any value.
Description
When a user is depositing assets, the amount field is not properly sanitized to accept only numeric values. Although there is a warning message stating that the input should be a positive number, a user can still input any value (or leave it empty), triggering a zero-value transaction that only consumes gas. Moreover this transaction was observed firing without "Starting a game" first, which the application requires before depositing an amount.
Impact
Zero-value transactions consume gas without producing meaningful state. Combined with the missing "start game" precondition, this is a low-cost griefing vector that any authenticated user can trigger.
Recommendation
Sanitize the deposit amount at the input boundary (numeric-only, positive, non-empty) and again at the Approve handler. Reject the transaction client-side before signing if the amount is invalid. Server-side, reject deposit attempts whose value is zero or empty.
Hopium: Acknowledged. Zealynx: Acknowledged.