Payouts
Top 25
Top 50
All
Sherlock
Jun '25
high
Anyone can steal refunds intended for Solana receivers
high
GatewayTransferNative can be drained via ETH_ADDRESS token collection bypass
medium
Cross-chain swaps will fail for USDT
medium
On-chain slippage calculation can cause user to lose all funds
medium
ETH refunds are always lost due to incorrect transfer logic in onRevert
medium
Bitcoin refunds in onRevert are sent to uncontrolled EVM Addresses and permanently lost
medium
Bug in AccountEncoder causes wrong Solana account permissions
medium
GatewayTransferNative does not collect platform fee when native asset is bridged
Apr '25
Jan '25
high
Invalid index used to fetch auction's address will prevent any auction from successfully ending
high
Fee beneficiary can miss collecting the fees due to the broken calculation
medium
Underflow in collateral calculation can cause inability to redeem
medium
Attacker can drain most of the reserves by weaponizing USDC blacklisting