attacker Can create a denial of service for the EOA that deployed the contract
attacker Can create a denial of service for the EOA that deployed the contract
Anyone call the unwrapAndSendETH
and steal all the funds to their address account
manual
1.remove the function
or
2. add a function modifier
or
3. Add a mapping that tracks how much a user sent to the contract and let that user deposited value be
used when a user wants to make a withdraw
or
4.The address that sends funds should be the only one that can make a withdrawal: using this code
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.