The Flow EVM contract defines important functionality to allow Cadence code and Flow SDKs to interface with the Ethereum Virtual Machine environment on Flow. The EVM contract emits events when relevant actions happen in Flow EVM such as creating new blocks, executing transactions, and bridging FLOW. This contract also defines Cadence-Owned Account functionality, which is currently the only way for Cadence code to interact with Flow EVM. Additionally, functionality is provided for common EVM concepts such as addresses, balances, ABIs, transaction results, and more. Overall the code is heavily delegated to external dependencies, such as `InternalEVM`, and other cadence contracts, `Crypto`, `NonFungibleToken`, `FungibleToken`, and `FlowToken` which were outside the scope of this audit. We have not found any significant security vulnerabilities. We recommend auditing the external dependencies especially `InternalEVM`, to ensure that the EVM system on Flow works as intended. **Fix Review Update:** The team has fixed the findings and suggestions in this report. Any new code beyond these fixes was not reviewed and is out of scope.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Acknowledged | - | - | - | - | 0 |
Fixed | 1 | - | - | - | 1 |
| Total | 1 | 0 | 0 | 0 | 1 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |