The withdraw function is restricted to the host of the contract through the onlyHost modifier. It transfers the entire balance of WETH, WBTC, and USDC tokens from the contract to the host's address. There is no check to ensure that the withdrawal is only allowed after a certain deadline. This means the host can withdraw funds at any time, even before the intended deadline, which could be against the intended use case of the contract.
the host can withdraw the balances before other participants have settled, potentially disrupting the system's intended flow.
Manual , vs code
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.