Security tools
| # | Project | Language | Description |
|---|---|---|---|
| 1 | solray | Rust | Solidity source code explorer for manual review |
| 2 | ripfuzz | Rust | High-throughput, coverage-guided, mutational fuzzer for Solidity smart contracts |
| 3 | ripfuzz-std | Solidity | ripfuzz standard library |
| 4 | cmdtest | Zig | Library to test any CLI |
Latest contributions
| # | Project | Language | Severity | Finding |
|---|---|---|---|---|
| 1 | Malda | Rust | Medium | get_proof_data_zkvm_input panics if chain_id=1 and l1_inclusion=true ↗ |
| 2 | DODO | Solidity | High | Invalid Check in GatewayCrossChain.claimRefund Allows Anyone To Claim Refunds Intended for Non-EVM Addresses ↗ |
| 3 | DODO | Solidity | High | Missing params.toToken == decoded.targetZRC20 Validation in GatewayCrossChain.onCall Allows Anyone to Drain Arbitrary decoded.targetZRC20 from GatewayCrossChain ↗ |
| 4 | DODO | Solidity | High | Empty swapData in GatewayTransferNative.onCall Bypasses Swap and Allows Draining of Arbitrary targetZRC20 ↗ |
| 5 | DODO | Solidity | High | GatewayCrossChain.onCall Swaps Arbitrary Contract's ZRC20 When swapDataZ.fromToken Mismatches Deposited zrc20 ↗ |





