
Payouts

Top 10

Top 25

Top 50
All
Sherlock
Aug '25
Jul '25
Jun '25
high
An attacker can claim refunds on behalf of other users if their wallet addresses are not 20 bytes long
high
The `amount` input in the `withdrawToNativeChain` function can be more than `msg.value` if user tries to withdraw by native token
medium
Using ERC20 Transfer Function Without Checking for Success in the `GatewaySend` Contract