Unprotected call to a function sending token to an arbitrary address.
function sendToL1 in L1BossBridge.sol
it can be used to empty the balance of the vault
Ensure that an arbitrary user cannot withdraw unauthorized funds.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.