The signature issued by operator, can be replayed across different chains.
There is no chain.id in signed data. According to comments: L2 will have a similar mechanism for withdrawing tokens from L1 to L2
. So same signature can be used for withdrawing.
As specified by the EIP4337 standard to prevent replay attacks ... the signature should depend on chain.id.
Manual Review
Include chain.id in hashed data
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.