https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

Ob

Security Researcher

Contact Me

High

1

Total

Medium

5

Total

$277.00

Total Earnings

#1663 All Time

1x

Payouts

regular

1x

Top 25

regular

1x

Top 50

All

Sherlock

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

277.12 USDC • 6 total findings • Sherlock • Ob

#21

high

Attacker can directly steal all tokens held by GatewayCrossChain via onCall.

medium

Attacker can maliciously send revert messages to the DODO gateway to crowd out legitimate reverts.

medium

Uniswap v2 pair check is not sufficient

medium

onRevert will send BTC to wrong address.

medium

`GatewaySend.onRevert` cannot handle ETH transfer

medium

Cross-chain swaps do not allow specifying slippage