Payouts
Top 10
Top 25
Top 50
All
Code4rena
Cantina
CodeHawks
Jan '25
high
high
medium
medium
Nov '24
Oct '24
high
high
Sep '24
medium
Aug '24
high
There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` function
high
Anyone can manipulate user nonce (nonce_manager) in settlement contract
high
settlement.cairo doesn't process callback correctly leading to CrossChainMsgStatus marked as SUCCESS even if it failed on destination chain
high
In Starknet already processed messages can be re-submitted and by anyone
high
handler's `receive_cross_chain_callback()` will always set the tx_status to `SETTLED` on source chain & burn the tokens (MintBurn Mode) even when the msg fails on destination
medium
Does not check if to_chain and to_handler is whitelisted in cross_chain_erc20_settlement
high
medium
medium
Jul '24
Jan '23
Dec '22