Skip to content
Field reportAU-2026-0275

Nineteen findings, none critical, six still open

OpenZeppelin's review of the Across V5 bridging extensions is more useful for what stayed unresolved than for what was fixed.

2 minSmart Contract Audits

OpenZeppelin has published its audit of the Across V5 bridging system, covering four pull requests across two repositories between 6 and 22 July. The scope was the extensions that let the V5 gateway and execution layer talk to the existing hub-and-spoke bridge, including counterfactual wallet support and HyperCore swap adapters.

The tally: 19 issues, none critical and none high. Two medium, both resolved. Seven low, of which three resolved. Eight notes, seven resolved. Twelve of nineteen closed, one partially.

The two mediums

  • No Core-side recovery path on the HyperCoreTransferAdapter for balances that get stranded.
  • Missing pre-delivery approval in the CounterfactualDestinationExecutor, which broke adapter-mode SpokePool fills.

Both are fixed. The more interesting reading is in the low-severity list, where the descriptions carry more weight than the label: an unverified correspondence between coreIndex and token that could misdirect funds, stable floors truncated in a way that makes them indistinguishable from unpriced pairs, forgeable context permitting an executor balance sweep, and a compromised OApp able to inflate transfer amounts through the OFTAdapter.

Four of those seven remain open. Severity ratings describe likelihood as much as impact, and on a bridge the conditions that make an unlikely path likely are exactly what an attacker gets to choose.

Two issues were raised by the client rather than the auditor, and neither is resolved. That is worth noting on its own: the team found things it has not yet closed, and published the fact.

Retold from OpenZeppelin. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined