Audit report published Oct 2025. Solidity.
| Severity | Count |
|---|---|
| High | 3 |
| Medium | 2 |
| Low | 2 |
| Informational | 4 |
| Total | 11 |
Safe Edges reviewed the Xenea Bridge contracts in October 2025. Eleven issues were identified: three High, two Medium, two Low and four Informational, two of which are gas optimisations. The High issues covered signature malleability, cross-chain signature replay and an unprotected initializer on the upgradeable implementation, and all three were fixed. Eight issues were fixed in total and three were acknowledged.
H-01 Insufficient Signature Malleability Check in SignatureUtils:recoverSigner — ResolvedH-02 Insufficient Multi-Chain Replay Attack Protection in SignatureUtils Contract — ResolvedH-03 Missing Constructor and _disableInitializers() to Prevent Unauthorized Initialization — ResolvedM-01 Missing Call to __UUPSUpgradeable_init() in Xenearaft:initialize — ResolvedM-02 Potential Returndata Gas Bomb Attack in Xenearaft:unlock — AcknowledgedL-01 Missing Zero-Address Validation Leading to Potential State Corruption — ResolvedL-02 Missing Explicit Function to Set and Validate Fees in Xenearaft — AcknowledgedI-01 Use Ownable2StepUpgradeable Instead of OwnableUpgradeable — ResolvedI-02 Missing Event Emissions for Significant State Changes — ResolvedG-01 Use external Instead of public for Gas Optimization — AcknowledgedG-02 Use Custom Errors Instead of require Statements to Save Gas — ResolvedSend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.