Beginner FriendlyFoundryBridge
100 EXP
View results
Submission Details
Severity: high
Valid

Send token to arbitrary destination in sendToL1

Summary

Unprotected call to a function sending token to an arbitrary address.

Vulnerability Details

function sendToL1 in L1BossBridge.sol

Impact

it can be used to empty the balance of the vault

Tools Used

Recommendations

Ensure that an arbitrary user cannot withdraw unauthorized funds.

Updates

Lead Judging Commences

0xnevi Lead Judge about 2 years ago
Submission Judgement Published
Validated
Assigned finding tags:

sendToL1(): Wrong function visibility

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!