Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
CodeHawks
Hats Finance
Mar '25
Jan '25
Aug '24
high
`ChakraSettlement.receive_cross_chain_msg` and `ChakraSettlement.receive_cross_chain_callback` functions do not ensure that receiving `ChakraSettlement` contract's `contract_chain_name` must match `to_chain` corresponding to respective `txid` input though
high
In Starknet already processed messages can be re-submitted and by anyone
high
handler's `receive_cross_chain_callback()` will always set the tx_status to `SETTLED` on source chain & burn the tokens (MintBurn Mode) even when the msg fails on destination
medium
Does not check if to_chain and to_handler is whitelisted in cross_chain_erc20_settlement
Jul '24
Jun '24
high
ThorChain will be informed wrongly about the unsuccessful ETH transfers due to the incorrect events emissions
medium
Due to the use of `msg.value` in for loop, anyone can drain all the funds from the `THORChain_Router` contract
medium
[M-02] Incorrect call argument in `THORChain_Router::_transferOutAndCallV5`, leading to grief/steal of `THORChain_Aggregator`'s funds or DoS
Apr '24
Jan '24
Nov '23
medium
Oct '23
Sep '23
Aug '23
Jul '23
Jun '23
May '23
Mar '23
Jan '23
Aug '22
Jul '22