DittoETH

Ditto
DeFiFoundryOracle
55,000 USDC
View results
Submission Details
Severity: low
Invalid

Ether can get stuck inside the rETH bridge

Summary

As there is a receive function, inside the rETH bridge but no function to withdraw ETH without providing zETH, ether could get stuck inside this contract.

Vulnerability Details

In case of an unintentional transaction, or through bugs in the bridge contract, rETH token contract, or contracts which will be implemented in the future, it could happen that ETH is sent to the bridge contract, which does not leave the contract directly again. There is no way implemented to withdraw this ETH and therefore it would be stuck inside the contract.

Impact

ETH could get stuck inside the rETH bridge contract.

Tools Used

Manual Review

Recommendations

Implement a function that allows (the DAP and / or admin) to withdraw excess ETH from the contract would be good practice.

Updates

Lead Judging Commences

0xnevi Lead Judge
almost 2 years ago
0xnevi Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Users sending ETH/native tokens

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.