Payouts
Top 10
Top 25
Top 50
All
Code4rena
Cantina
Feb '25
Jan '25
Sep '24
high
high
Aug '24
high
There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` function
high
Anyone can manipulate user nonce (nonce_manager) in settlement contract
high
The LockMint and BurnUnlock modes cannot be used
high
In Starknet already processed messages can be re-submitted and by anyone
medium
Does not check if to_chain and to_handler is whitelisted in cross_chain_erc20_settlement
Jul '24