A bridge is only as strong as the weakest assumption in its message path, and that path usually crosses several trust domains: contracts on both chains, a relayer set, a signature or MPC scheme, and often a backend that decides what gets relayed at all. Reviewing only the contracts leaves most of the attack surface unexamined.
We audit the whole path — including the off-chain components — which is where a meaningful share of our cross-chain findings have been.
Tell us what you're building. Bridge and Cross-Chain Security Audits is an area we work in constantly.