In the current implementation, when a message is canceled, the system does not refund the user the ETH that was initially spent.
This can lead to a loss of funds for the user, creating a potential financial risk within the system.
When a user cancels a message, the intended logic should ideally refund the ETH spent during the transaction. However,
the existing codebase lacks this refund mechanism. As a result, users who cancel their messages lose the ETH they spent,
which is neither returned to their account nor utilized in any other manner.
Eth are lost and not refunded if a bug accor in L2 contracts.
Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.