
[Fig. 01]
Hexens is a hidden gem. Their attention to detail is unmatched. We started working with them for a single project to test them out but loved them so much that we gave them two more projects before the first engagement even got completed. They actually care about security and customer experience.
Stealing ETH using discount factor bypass
Withdrawal proofs can be forged due to missing index bit size check
Missing constraint in PIL leading to proving fake inclusion in the SMT
Infinite voting power
Oracle DoS by depositing into a withdrawn validator
Locking and staking arbitrary amount of tokens without paying
Positive price movements of vault assets can be directly stolen through withdraw
Decimal precision oversight in cross-layer token transactions