Signature can be re-used.
Signature replay allows malicious actors to withdraw funds to move a users funds (albeit only to the wallet they specified). A key invariant of the bridge is broken when a signature can be successfully used more than once.
Bridge allows user to specify the l2 recipient, therefore it which could quite realistically be used for debt settlement. This vulnerability would allow the recipient of such a transaction to drain the users funds.
Manual review
Ensure nonce and chainID is used when generating signature.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.