withdrawTokens
function in L1 bridge contract should not be payable. Withdrawing tokens from bridge doesn't require any ETH currently. User may accidentally send ether with this call. As there is no sweep function, ETH sent will be stuck in contract.
Remove payable for withdrawTokens
Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.