Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
Immunefi
Aug '25
Jul '25
Jun '25
high
medium
high
Improper address validation allows unauthorized refund claims via `claimRefund` bypassing `bots` mapping
high
Bypass of asset verification in `GatewayTransferNative::withdrawToNativeChain` enables theft of contract-held tokens via malicious ZRC20 message payload
medium
Fee deduction logic mismatch causes incorrect amount processing in `GatewayTransferNative::onCall`
medium
Griefing vulnerability via external ID collision in `GatewayCrossChain::onCall` leading to refund data overwrite
May '25
high
medium
medium
high
high
high
high
Apr '25
high
high
high
medium
Mar '25
high
medium
Feb '25
medium
medium