Beginner FriendlyFoundryBridge
100 EXP
View results
Submission Details
Severity: high
Valid

Malicious Signer can call arbitrary contract and send ETH

Summary

Malicious Signer can use the sendToL1 method to send to his account ETH if there are in the bridge.

Impact

Low

Tools Used

manual

Recommendations

Make the sendToL1 method private or internal.

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

sendToL1(): Wrong function visibility

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.