Lack of verification if the sender has first originated a successful deposit
In L1BossBridge::withdrawTokensToL1 there is no verification process to ensure that the caller has first originated a successful deposit of an amount at least egals to the amount to be withdrawn in the L1 part of the bridge.
Anyone can withdraw tokens without first depositing any.
Manual review
Before executing withdrawal, check if the sender has previously successfully deposited a sufficient amount of tokens either in L1 or L2.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.