Beginner FriendlyFoundryBridge
100 EXP
View results
Submission Details
Severity: low
Invalid

No cancel deposit functionality

If a user deposits by calling L1BossBridge::depositTokensToL2, there is no way to withdraw directly from the L1.

Vulnerability details

Instances where a user may want to cancel their deposit include: users erroneously depositing to the bridge, changing their mind about bridging their tokens, and sending an incorrect amount. If a user wants to cancel their deposit and be able to withdraw directly from the L1, they will not be able to since there is no cancel functionality.

Impact

Users would have to withdraw from the L2, deposit back to the L2, and then withdraw from the L1. This is a costly and time-consuming process.

## Recommended mitigation

Add a cancel function for users to withdraw directly from the L1.

Updates

Lead Judging Commences

0xnevi Lead Judge
almost 2 years ago
0xnevi Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.