First Flight #4: Boss Bridge

Beginner FriendlyFoundryBridge
100 EXP
Submission Details
Severity: high
Valid

Malicious signer can drain all the funds from the vault by signing the withdrawal message hash for self.

Updates

Lead Judging Commences

0xnevi Lead Judge 11 months ago
Submission Judgement Published
Validated
Assigned finding tags:

withdrawTokensToL1()/sendToL1(): signature replay

shikhar229169 Submitter
11 months ago
0xnevi Lead Judge
11 months ago
0xnevi Lead Judge 11 months ago
Submission Judgement Published
Validated
Assigned finding tags:

withdrawTokensToL1(): No check for deposits amount

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.