Bryan Pellegrino, CEO of LayerZero, posted a message on the X platform last night to call out the Across Protocol team, saying that the latter's protocol contract has a vulnerability that allows the contract owner to withdraw tokens from any address at any time, or to zero the balance of any account.
This morning, the third-party security company Trust Security called out the LayerZero team with almost the same words as Bryan, saying that there is a similar vulnerability in its protocol contract, allowing the contract owner to withdraw tokens from any address at any time, or to exhaust any Stargate pool.
It is worth mentioning that when Bryan called out Across Protocol, he mentioned that the team should reward LayerZero according to the bug bounty program. Trust Security also called out Bryan, saying that LayerZero's bug bounty program claims to provide 10% of risk funds as a reward, so LayerZero should give Trust Security a bonus of more than $400 million, or publicly admit that it is just slandering other projects for traffic.