complete
findings
Identified three issues: a high-severity nonce/DoS risk on failed execTransaction, a medium unchecked-return-data false-success risk, and a low cross-chain signature replay risk from a minimal domain separator.
Top findings
-
high
Failed execTransaction still consumes tezosOperation, enabling gas‑griefing DoS and stuck unwraps
-
medium
execTransaction ignores return data, so ERC20 transfers that return false are treated as successful
-
low
Domain separator omits chainId, allowing cross‑chain signature replay