owner_l1
is not being checked for zero address in deposit_tokens
function
No validation is performed if owner_l1
is zero address. If user accidentally sets the owner_l1
to zero address, the message can never be consumed on L1 bridge resulting NFts loss
Loss of NFTs
Manual review
Revert if onwer_l1
is zero address
Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.