Can anyone find any Vulnerbility or Bugs In this function?

Viewed 40

I have implemented this function and I think it has some Bugs and vulnerabilities this function so anyone can you help me to find the Vulnerability and bugs. I'm confused in this line

uint balance = address(this).balance; 

and the next line to transfer the balance so is it possible for the hacker to use this line and transfer all the balance in his wallet?

function rescueNative() external{ 
        require(msg.sender == owner, "only owner");
        uint balance = address(this).balance;
        owner.transfer(balance);

        emit NativeRescued(address(this), balance);
    }
1 Answers

If the value of owner is a smart contract address, one of two errors can happen:

  1. If the owner contract doesn't implement the fallback() nor receive() special functions, the transfer() fails. Since your contract uses a deprecated Solidity version (it was not required to use transfer() on address payable, only on address in pre-0.8 versions), please also note that the fallback function in some older versions was a function without a name - simply function () {}

  2. If the owner contract reenters the rescueNative() function from within its fallback or receive function, this might cause overflow if there's more than 1024 subsequent calls.

Other than that - assuming that this is a standalone function, not possible to call it from any other function, and that the owner is an EOA or a contract that is able to correctly receive funds, this snippet doesn't seem to show any more vulnerabilities.

Related