NFTBridge
60,000 USDC
View results
Submission Details
Severity: low
Invalid

Eth could get stuck in the `addMessageHashForAutoWithdraw` function

Summary

the function `addMessageHashForAutoWithdraw` is payable but there is no accounting for the possible ETH sent

Vulnerability Details

this means that any ether sent in this function is lost and not recoverable

Impact

any eth sent in this function is stuck in this contract

Tools Used

manual audit

Recommendations

consider making this function not payable

Updates

Lead Judging Commences

n0kto Lead Judge 12 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
Assigned finding tags:

Informational / Gas

Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.