Payouts
Top 10
Top 25
Top 50
All
Sherlock
Cantina
Jun '25
high
Invalid Check in `GatewayCrossChain.claimRefund` Allows Anyone To Claim Refunds Intended for Non-EVM Addresses
high
Missing `params.toToken == decoded.targetZRC20` Validation in `GatewayCrossChain.onCall` Allows Anyone to Drain Arbitrary `decoded.targetZRC20` from GatewayCrossChain
high
Empty `swapData` in `GatewayTransferNative.onCall` Bypasses Swap and Allows Draining of Arbitrary `targetZRC20`
high
`GatewayCrossChain.onCall` Swaps Arbitrary Contract's ZRC20 When `swapDataZ.fromToken` Mismatches Deposited `zrc20`
medium
`GatewayTransferNative.withdraw` Truncates 32-Byte Bitcoin Addresses in `revertMessage`
May '25
medium
high
high
high
high
high
high
high
Apr '25
high
high