Other chain and infrastructure vulnerabilities in disclosed reports

Wallets, node software, exchange infrastructure and chains outside the four major virtual machine families.

Reports indexed
2
Total paid
$2k
Critical
0
Largest payout
$2k

Not every crypto disclosure is a contract bug. Wallet key handling, transaction-signing UX that misrepresents what is being approved, node RPC exposure, and exchange-side account and withdrawal logic all sit here — and the payouts are frequently larger than contract findings because the blast radius is custodial.

This bucket also holds chains and runtimes outside the main four: UTXO chains, privacy chains, and purpose-built L1s whose failure modes do not map onto the EVM vocabulary.

Because the surface is heterogeneous, the vulnerability category filter is the more useful lens on these reports than the chain filter alone.

What reviewers look for

  • Key material reachable from a lower-trust process or an unencrypted store
  • Signing prompts that misrepresent the transaction being authorised
  • Node RPC methods exposed without authentication
  • Withdrawal and account-recovery logic on custodial infrastructure
  • Consensus or mempool behaviour specific to a non-EVM runtime

Curated highlights

The largest disclosed payouts in this group, with our own summary of each. Every report links back to the original disclosure.

Vulnerability classes seen on this chain

Related chain / vm pages