DeFiHardhatOracleProxyUpdates
100,000 USDC
View results
Submission Details
Severity: low
Invalid

unwrapAndSendETH() can drain UnwrapAndSendETH.sol

Summary

unwrapAndSendETH()can drain UnwrapAndSendETH.sol

Vulnerability Details

unwrapAndSendETH() lack of access control.
Anyone can use unwrapAndSendETH() to drain UnwrapAndSendETH.sol.

Impact

Anyone can call the unwrapAndSendETH() to unwrap WETH into ETH and send it to their, thus stealing funds from the contract.

Tools Used

Recommendations

Add access control check.

Updates

Lead Judging Commences

giovannidisiena Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Design choice
Assigned finding tags:

Pipeline access control

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.