User might bridge his NFT to different chain, and once that collection would be removed from the whitelist by its owner, he won't be able to bring it back to the original chain.
That check present in deposit_tokens
function would not allow to bridge it.
User would have his original NFT locked in the escrow.
Manual Review
Once the collection is not supported, the protocol should still allow to bridge the NFT to its original chain.
Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.