This UnwrapAndSendETH::unwrapAndSendETH
have no access control and didn't check who deposit token or ether allow any one to call and withdraw all the fund store in this token.
If you see the contract function any one can deposit small amount of weth and transfer all the ether and with from token no matter who deposit it, also front run
let suppose person A send some token and Attacker found it transaction and before he can withdraw he front run the transaction and get all the amount transfer to his account.
Lose of Funds
Manual Review
Access access control or check who deposit the amount , so that can withdraw the amount from contract
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.