We audited the cross-chain token bridge of a live AI-agent protocol. Our AI found 3 critical-severity flaws — the kind of bugs that have drained real bridges. Details are withheld under responsible disclosure.
We found that a transfer identifier can collide across chains, allowing the same transfer to be claimed more than once — potentially draining bridge liquidity. This is the pattern behind several real bridge exploits.
Full exploit mechanics withheld. Project owners: contact for the report.
We found that a claim path does not fully verify the recovered signer, opening a forgery surface.
A signed message is not bound to a specific chain, enabling cross-chain replay.
Three critical flaws in a live bridge, found by AI in minutes. If your protocol has a bridge, this class of bug matters.