Anyone can withdraw funds from bridges by calling withdraw
and unstakeEth
.
withdraw
and unstakeEth
do not check for any form of authorization. Any address can withdraw funds from a bridge.
For example:
Attackers could drain bridge funds.
Manual
Add an access control check in withdraw
and unstakeEth
to restrict access.
For example:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.