the function `addMessageHashForAutoWithdraw` is payable but there is no accounting for the possible ETH sent
this means that any ether sent in this function is lost and not recoverable
any eth sent in this function is stuck in this contract
manual audit
consider making this function not payable
Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.