The _whiteListCollection
function allows adding collections to the whitelist, but there’s no check to ensure that only valid collections are added. This means that any address, including potentially malicious or incorrect addresses, could be added to the whitelist without verification.
If a malicious or incorrect collection address is added to the whitelist:
Users might unknowingly interact with unauthorized or fake collections.
Assets could be misrouted, lost, or stolen if they are sent to or from a malicious address.
The integrity of the bridge could be compromised, leading to loss of trust and potential financial damage.
Add checks to ensure that only valid and verified collections can be added to the whitelist.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.