Payouts
Top 25
Top 50
All
Sherlock
Jul '25
Jun '25
high
Improper address validation allows unauthorized refund claims via `claimRefund` bypassing `bots` mapping
high
Bypass of asset verification in `GatewayTransferNative::withdrawToNativeChain` enables theft of contract-held tokens via malicious ZRC20 message payload
medium
Fee deduction logic mismatch causes incorrect amount processing in `GatewayTransferNative::onCall`
medium
Griefing vulnerability via external ID collision in `GatewayCrossChain::onCall` leading to refund data overwrite
Mar '25