Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The published Hyperliquid bridge audits document historical issues in Solidity contracts scoped to Arbitrum snapshots—not a security verdict on every Hyperliquid transfer route or on a current deployment. Zellic reported that a nested reentrancy guard prevented withdrawals from being finalized in the code it reviewed and recorded a fix commit. Cyfrin separately reported signature-validation and initialization issues. Neither report establishes whether its fixes are present in production today.

Which Hyperliquid bridge did the audits examine?

“Hyperliquid bridge” can refer to different systems and code versions. The two reports discussed here concern legacy Solidity bridge contracts on Arbitrum. They do not audit HyperEVM as a whole, transfers between HyperCore and HyperEVM, or third-party routes for moving assets from other chains.

Hyperliquid’s audit index identifies the Zellic report as covering the legacy bridge contract. The reports name different contracts and repository snapshots, so their findings should not be treated as one assessment of a single, unchanged codebase.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Report Contracts and snapshot Reported results
Zellic, 2023 Bridge2 and Signature on Arbitrum, repository commit 43b5267c58778e5e24640c9abac06cb608d63c40 Six findings: zero critical, one high-impact, one medium-impact, and four informational.
Cyfrin, 2023 Bridge.sol and Signature.sol, repository commit e0aff46 Two medium findings marked resolved and one low finding marked acknowledged, as well as informational observations.

These are each auditor’s report-specific classifications, not a combined vulnerability total or a shared severity scale. Zellic’s assessment report and Cyfrin’s security review provide the scope and details for their respective findings.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What did Zellic find about withdrawal finalization?

Nested reentrancy guards blocked batched finalization

Zellic found that batchedFinalizeWithdrawals called the private finalizeWithdrawal function, while both functions were marked nonReentrant. In the reviewed snapshot, the inner call therefore encountered the reentrancy guard already entered by the outer call, causing finalization to revert. The report described the result as withdrawals being impossible to finalize in that code.

Zellic classified this as high impact. Its report records that contributors acknowledged the issue and implemented a fix in commit e5b7e068. That records a code change, not confirmation that a particular live deployment runs the fixed code.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Pending disputed operations could survive a pause

The same report describes validator-approved operations that wait through a dispute period. It found that if a malicious withdrawal was detected and the contract paused, pending operations could not be removed. In the audited snapshot, an operation could remain pending and be processed after unpausing. The report records a remediation commit, 8c4a182a.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is a lifecycle and authorization concern: pausing may stop activity temporarily without canceling already-pending actions. The finding and recorded remediation apply to the reviewed snapshot; they do not establish the behavior of a current deployment.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What did Cyfrin report about signatures and validator updates?

Cyfrin’s review covers an earlier contract snapshot than Zellic’s. Its summary marks two medium-severity findings resolved and a low-severity finding acknowledged. The detailed findings include two issues relevant to how bridge authority is established:

  • Signature and validator-set validation: Cyfrin reported bad signature recovery, signature malleability, and missing zero-address protection in updateValidatorSet. The summary marks this finding resolved.
  • Initialization and power thresholds: Cyfrin also reported a problem involving initialization and power-threshold validation. Its summary marks this medium finding resolved.

“Resolved” is the status recorded in that report. It does not, by itself, verify that the change was deployed to a particular contract address or remains in the code now in use. See the Cyfrin report for the finding descriptions and statuses.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does this relate to moving assets to HyperEVM?

Hyperliquid’s onboarding documentation asks both “How do I bridge assets to the HyperEVM from another chain?” and “How do I move assets to and from the HyperEVM?” Those questions concern distinct flows. The audited legacy Arbitrum contracts should not be assumed to handle every route described in the onboarding guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The HyperEVM developer documentation describes HyperEVM as part of Hyperliquid execution, with HYPE as native gas, mainnet chain ID 999, and JSON-RPC endpoint https://rpc.hyperliquid.xyz/evm. The HyperEVM onboarding guide describes transfer controls for moving assets between HyperCore spot balances and HyperEVM, and separately lists third-party bridges and swaps for assets arriving from other chains. These descriptions are context for distinguishing routes; they do not expand the scope of the legacy bridge audits.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The onboarding guide warns that the HYPE transfer address works only for HYPE. Sending other assets to it can result in their loss. Check the asset and destination instructions for the specific route you intend to use rather than assuming a transfer control or third-party route is covered by the historical audit.

What do these audit reports establish—and what do they not?

Zellic lists three consultants and four person-days, with a primary review on July 10–12, 2023 and a closing call on August 8, 2023. Its report says the engagement excluded other Hyperliquid smart contracts, off-chain components including validators, front-end components, project infrastructure, and key custody. It also cautions that time-boxed assessments have coverage limits.

Cyfrin describes a one-week review limited to security aspects of the Solidity implementation and says a Rust test file was excluded. These boundaries matter because a contract review cannot, on its own, establish the security of excluded systems or continuing production operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The available reports do not identify the exact deployment a reader might mean today or verify its bytecode, administrative roles, pause state, or whether every recorded remediation is present in production. They therefore support a historical account of findings and report statuses—not a claim that a current bridge is vulnerable, safe, or unchanged.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.