The withdraw function allows the contract owner to withdraw all ETH from the contract to any arbitrary address. While it is protected by onlyOwner, there are no sanity checks or event logs, and no access control for emergency situations or multi-sig requirements.
Likelihood
One transaction can transfer entire balance.
No destination check, no timelock, no logging.
Impact
Full ETH loss for users.
No visibility or recoverability.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.