NFTBridge
60,000 USDC
View results
Submission Details
Severity: low
Invalid

Withdraw function should not be payable

Details

withdrawTokens function in L1 bridge contract should not be payable. Withdrawing tokens from bridge doesn't require any ETH currently. User may accidentally send ether with this call. As there is no sweep function, ETH sent will be stuck in contract.

Recommendations

Remove payable for withdrawTokens

Updates

Lead Judging Commences

n0kto Lead Judge 11 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
Assigned finding tags:

Informational / Gas

Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.