[{"severity":"Medium","reward":27.253880846508437,"issues":[{"number":32,"title":"A single borrower being written off will create unbacked stablecoins for all users","author":"Valves"},{"number":152,"title":"Loss of Debt Tracking (Zombie Debt) on `WriteOff` when There is Only One Borrower","author":"JuggerNaut"},{"number":246,"title":"Protocol will become insolvent when last borrower is written off as bad debt vanishes","author":"legalwarden50"},{"number":256,"title":"[HIGH] Single undercollateralized borrower will erase all system debt and leave Monolith stablecoin holders with unbacked coins","author":"Draxen"},{"number":296,"title":"Malicious borrower will steal 100% of borrowed funds and recover collateral from the Protocol","author":"flora2627"},{"number":348,"title":"A sole borrower will erase debt and leave stablecoin supply unbacked","author":"neeloy"},{"number":363,"title":"WriteOff Debt Deletion Creates Unbacked Stablecoin Supply","author":"0x97"},{"number":406,"title":"Liquidator will create permanent unbacked stablecoin supply breaking protocol solvency for all coin holders","author":"piyushmali"},{"number":416,"title":"debt loss and protocol Insolvency on last Borrower Write-Off","author":"securehash1"},{"number":423,"title":"Write-off Procedure Can Obliterate System Debt and Disable Redemptions","author":"jo13"},{"number":539,"title":"`writeOff()` Can Zero Total Debt While Coin Supply Remains","author":"jayjoshix"},{"number":655,"title":"`writeOff()` Can Zero Total Debt When the Written-Off Account Is the Last Borrower","author":"Edoscoba"},{"number":700,"title":"Last borrower can erase debt via `writeOff` when collateral crashes","author":"cyberEth"},{"number":732,"title":"If there's only a single user which has reached a state with bad debt, anyone can mint unbacked tokens.","author":"bughuntoor"},{"number":987,"title":"Bad Debt Socialization Fails When No Other Borrowers Exist","author":"PowPowPow"},{"number":1047,"title":"WriteOff skips redistribution when sole borrower, creating insolvency","author":"0xnija"},{"number":1058,"title":"`writeOff()` can erase all protocol debt when the last borrower is written off (unbacked COIN)","author":"legat"},{"number":1102,"title":"[H-1] WriteOff Function Creates Unbacked Stablecoin When Last Borrower is Liquidated","author":"frustramatic"},{"number":1114,"title":"Debt Disappearance via writeOff() with totalDebt=0","author":"SnowX"},{"number":1205,"title":"A caller will break debt accounting and leave unbacked Coin in circulation for the protocol as they will writeOff the last remaining borrower","author":"DSbeX"},{"number":1255,"title":"Total Bad Debt Is Not Cleared from the System when the last standing user debt is written off","author":"Riceee"},{"number":1275,"title":"An attacker can exploit continuous writeOff in an empty market to allow minting unbacked tokens when bad debt exists","author":"deadmanwalking"},{"number":1349,"title":"`writeOff()` Can Erase System Debt When the Target Is the Last Borrower, Breaking Debt Accounting (`totalDebt < circulating supply`)","author":"zach223"},{"number":1418,"title":"Last borrower writeOff will cause unbacked stablecoin for all coin holders","author":"n0fr33w1f14u"},{"number":1424,"title":"The subsequent borrowers might face coin devaluation when first borrower is liquidated","author":"0xpiken"}]},{"severity":"High","reward":1654.6293524907446,"issues":[{"number":481,"title":"Free debt mode can be DOS-ed","author":"0xc0ffEE"},{"number":726,"title":"Any user can DoS free debt, making it impossible to open new positions or to redeem any assets.","author":"bughuntoor"},{"number":734,"title":"User can abuse rounding issue in order to borrow unbacked tokens","author":"bughuntoor"},{"number":784,"title":"Free Debt Shares Overflow via Large Redemptions Leading to Protocol Brick","author":"SOPROBRO"},{"number":848,"title":"Borrower can extract unbacked Coin at the expense of the protocol","author":"Valves"},{"number":1057,"title":"Attacker can inflate the share to asset ratio and DOS the Lender contract.","author":"wickie"},{"number":1198,"title":"Attacker will freeze collateral and unfairly liquidate redeemable borrowers","author":"Audittens"},{"number":1238,"title":"Unbacked token minting through share ratio manipulation when totalFreeDebt reaches zero","author":"deadmanwalking"},{"number":1310,"title":"There is a severe arithmetic vulnerability in the handling of 'Free Debt Shares' and the 'Epoch/Rebase' mechanism. This leads to an integer overflow, resulting in a Denial of Service (DoS) attack that renders the contract permanently paralyzed.","author":"songyuqi"},{"number":1366,"title":"Users can get stuck in paid debt mode and lose their entire collateral","author":"dandan"},{"number":1448,"title":"Arithmetic Overflow in Free Debt Share Calculation Causes Permanent Denial of Service for New Free Debt Borrowers","author":"Uddercover"}]},{"severity":"Medium","reward":15.414888985684643,"issues":[{"number":325,"title":"Comparator mismatch allows liquidation at borrowing limit; collateral transfer before repayment","author":"itsgreg"},{"number":415,"title":"Debt positions can be liquidated immediately after creation","author":"0xc0ffEE"},{"number":431,"title":"Liquidation condition allows solvent positions to be liquidated","author":"X0sauce"},{"number":451,"title":"Wrong comparison operator in `getLiquidatableDebt()` allows unfair liquidation","author":"AlexCzm"},{"number":467,"title":"Lack of safety buffer between liquidation thresholds and max LTV","author":"AlexCzm"},{"number":649,"title":"Solvency check leading to user's position being liquidated","author":"coffiasd"},{"number":729,"title":"Liquidator Can Trigger Liquidation at Exact Collateral Factor","author":"0xnightswatch"},{"number":766,"title":"Liquidation will occur immediately when a user borrows up to their maximum debt capacity","author":"0xpiken"},{"number":810,"title":"Inconsistency in position health checks will lead to the incorrect user liquidations","author":"0xeix"},{"number":815,"title":"Immediate Borrower Liquidation Through Improper Liquidation Flow Design","author":"ZafiN"},{"number":832,"title":"Premature liquidation of healthy positions at exact collateral factor threshold","author":"Bobai23"},{"number":839,"title":"Position can be liquidatable while simultaneously being considered healthy","author":"typicalHuman"},{"number":853,"title":"Instant Liquidation Risk When Borrowing at Maximum Collateral Factor","author":"futureHack"},{"number":923,"title":"Loans can be instantly liquidated","author":"air_0x"},{"number":939,"title":"Boundary condition mismatch allows liquidation of solvent positions at exact borrowing capacity","author":"algiz"},{"number":942,"title":"Inconsistent solvency and liquidation conditions in `adjust` and `getLiquidatableDebt` function.","author":"Aasif"},{"number":1016,"title":"``borrowingPower == debt`` is liquidatable in liquidate() function which contradicts solvency in ``adjust()``.","author":"0xTarnished"},{"number":1043,"title":"Borrowers with Health Factor 1.0 Can Be Unfairly Liquidated","author":"nodesemesta"},{"number":1046,"title":"No gap between borrow LTV and liquidation LTV allows instant liquidation at position open","author":"deadmanwalking"},{"number":1056,"title":"Incorrect boundary condition allows liquidation of positions that should be non-liquidatable","author":"queen"},{"number":1064,"title":"Liquidators will prematurely liquidate healthy borrowers due to an incorrect liquidation boundary","author":"Hemakhi"},{"number":1135,"title":"Positions where  `debtBalance = borrowingPower` is allowed in `adjust` function but can be liquidatable","author":"yaioxy"},{"number":1144,"title":"Off-by-One Error in Liquidation Threshold Causes Premature Liquidation of Solvent Borrower Positions","author":"KrisRenZo"},{"number":1231,"title":"Solvent Positions at Exact Borrow Limit Incorrectly Flagged as Liquidatable","author":"Riceee"},{"number":1239,"title":"due to the flaw logic Inconsistent Solvency Checks Cause Immediate Liquidation of Newly Created Positions","author":"LonWof-Demon"},{"number":1325,"title":"adjust function allows creating liquidatable positions","author":"0rpse"},{"number":1326,"title":"Borrowers at the max-LTV boundary are instant liquidated","author":"Le_Rems"},{"number":1350,"title":"Mismatch Between Solvency Validation and Liquidation Criteria Enables Instant Liquidation","author":"CovenantGuard_Sec"},{"number":1356,"title":"Edge-Case Solvency Mismatch Allows Immediate Liquidation of Fresh Positions","author":"Nyxx"},{"number":1460,"title":"It is possible to create a position that is instantly liquidatable","author":"0xSomeHuntoor"}]},{"severity":"Medium","reward":1120.8517349934764,"issues":[{"number":244,"title":"The function totalAsset from Vault Contract is not EIP 4626 compliant","author":"desaperh"},{"number":259,"title":"`Vault.totalAssets()` can revert, violating ERC4626 standard","author":"magickenn"},{"number":595,"title":"Vault's EIP violation creates a potential DoS.","author":"typicalHuman"},{"number":820,"title":"EIP violation for `totalAssets()` in the `Vault`","author":"0xeix"},{"number":1021,"title":"`Vault` breaks EIP-4626 in `totalAssets`","author":"axelot"}]},{"severity":"Medium","reward":130.2722781803013,"issues":[{"number":305,"title":"Undercollateralized borrowers will receive unfair debt reduction during redemptions","author":"zcai"},{"number":355,"title":"Redeemer will drain collateral from solvent borrowers","author":"neeloy"},{"number":621,"title":"`updateBorrower()` silently caps `bal < redeemedCollateral` without redistributing shortfall, causing protocol insolvency - last withdrawers lose everything","author":"blockace"},{"number":643,"title":"Redemptions Can Create a Collateral Deficit When a Free-Debt Borrower Is Underwater","author":"Edoscoba"},{"number":800,"title":"Redemptions can transfer collateral not recoverable from borrowers due to capped slashing","author":"Proof-of-Spirit"},{"number":819,"title":"Collateral accounting, Liquidation safety invariant violation","author":"DevBear0411"},{"number":842,"title":"Collateral Accounting Invariant Violation","author":"future"},{"number":1030,"title":"Underwater borrowers cause socialized collateral loss via redemption","author":"0xnija"},{"number":1103,"title":"Protocol Insolvency via Redemption Against Zero-Debt Redeemable Users","author":"gabkov"},{"number":1127,"title":"Accounting will be broken if a user redeems when there is a bad debt position","author":"bughuntoor"},{"number":1142,"title":"Unfair reduction of collateral for certain users","author":"xiaoming90"},{"number":1232,"title":"Redemption accounting can become undercollateralized: `redeem()` pays out collateral without conservatively redistributing borrower shortfalls, breaking collateral conservation and locking withdrawals","author":"legat"},{"number":1246,"title":"A liquidated borrower can steal collateral from Lender contract","author":"itsabinashb"},{"number":1333,"title":"`updateBorrower` redeem collateral cap can create a global collateral deficit, causing the coin to become undercollateralized","author":"deadmanwalking"},{"number":1445,"title":"Total Protocol Collateral Can Become Less Than Sum of User Collateral","author":"touristS"}]},{"severity":"Medium","reward":1.6207022239867606,"issues":[{"number":30,"title":"Incorrect scaling in interest calculation leads to interest loss","author":"0xl33"},{"number":156,"title":"Incorrect Interest Calculation Leads to Loss of Protocol Yield","author":"gabkov"},{"number":174,"title":"Unit mismatch in `calculateInterest` function causes massive interest undercharge","author":"0xodus"},{"number":198,"title":"Unit mismatch in `calculateInterest()`","author":"bbl4de"},{"number":217,"title":"InterestModel undercharges interest when decaying to `MIN_RATE` due to mis-scaled integral term","author":"v_2110"},{"number":224,"title":"System will undercharge interest due to incorrect scaling lenders","author":"zcai"},{"number":253,"title":"Precision loss in calculateInterest causes significant yield loss when interest rate decays to floor","author":"M1troV"},{"number":329,"title":"InterestModel floor crossing unit mismatch with PSM steering enables permanent interest underaccrual","author":"itsgreg"},{"number":349,"title":"Borrowers will underpay decay interest, reducing protocol/Vault yield","author":"neeloy"},{"number":366,"title":"InterestModel will miscalculate interest payments affecting borrowers and stakers","author":"m3dython"},{"number":381,"title":"Undercharging Interest When Borrow Rate Decays to MIN_RATE","author":"Edoscoba"},{"number":404,"title":"Unit mismatch in Interest calculations during Decay-to-Minimum Rate Transition","author":"securehash1"},{"number":425,"title":"Interest Undercharged when Borrow Rate Decays past MIN_RATE Due to Unit Mismatch in Integral Calculation","author":"rubencrxz"},{"number":438,"title":"Incorrect Interest Calculation in Rate Decay with Minimum Rate Floor","author":"ChainProof"},{"number":466,"title":"H-06: Borrowers will avoid paying accrued interest during rate decay periods causing loss of yield for Vault Stakers and the Protocol","author":"Albert_Mei"},{"number":477,"title":"Interest Model Severely Undercharges When Rate Decays Below MIN_RATE","author":"jayjoshix"},{"number":530,"title":"Interest Undercharged When Rate Decays to MIN_RATE","author":"emmanuel_ewah"},{"number":536,"title":"Interest Accrual Logic Flaw in `InterestModel`","author":"coin2own"},{"number":574,"title":"Missing WAD Normalization in Rate-Decay Floor Path Reduces Accrued Interest Drastically","author":"Matin"},{"number":603,"title":"exponential decay interest miscalculated by factor of 1e18 when rate reaches minimum","author":"blockace"},{"number":636,"title":"Decay phase interest effectively zeroed due to missing scaling factor","author":"0xShoonya"},{"number":650,"title":"Unit Mismatch in Interest Calculation Causes Significant Yield Loss When Rate Decays Below Minimum","author":"xxiv"},{"number":653,"title":"Unit mismatch in `calculateInterest()` undercharges interest when borrow rate decays to `MIN_RATE`","author":"algiz"},{"number":768,"title":"Unit Mismatch in Interest Calculation Causes ~99% Interest Loss During Rate Decay","author":"ibrahimatix0x01"},{"number":869,"title":"Incorrect Interest Normalization in InterestModel.calculateInterest() leads to under-accrual","author":"dic0de"},{"number":970,"title":"Borrowers will underpay interest owed to lenders","author":"ZeroEx"},{"number":977,"title":"Incorrect 1e18 scaling in MIN_RATE integral underestimates interest after hitting the floor","author":"dantehrani"},{"number":1004,"title":"Decay integral mis-scales interest to near zero","author":"0xnija"},{"number":1006,"title":"Unit mismatch causes borrowers to underpay interest when the rate crosses the minimum floor, reducing protocol revenue","author":"axelot"},{"number":1018,"title":"In the Contract `InterestModel.sol` the Formula used for the interest Calculation is Wrong as Per Docs and Code","author":"Himanshu772005"},{"number":1022,"title":"Incorrect precision handling reduces interest during high free debt ratio","author":"X0sauce"},{"number":1185,"title":"Incorrect interest calculation","author":"xiaoming90"},{"number":1274,"title":"The protocol loses significant interest revenue during the decay phase due to unit mismatch.","author":"ChaosSR"},{"number":1284,"title":"Borrowers will underpay interest when the borrow rate decays to MIN_RATE, harming lenders/stakers","author":"Harry-Elite"},{"number":1297,"title":"Borrowers will underpay interest for lenders due to truncation in floor-crossing integral leading to Interest accrual invariant violation","author":"cholakovvv"},{"number":1314,"title":"Incorrect scaling done in calculate interest function for a certain case.","author":"Varun_05"},{"number":1322,"title":"Paid debt users will not pay interest if it reaches `MIN_RATE`","author":"Audittens"},{"number":1346,"title":"Borrowers will underpay interest owed to lenders","author":"Le_Rems"},{"number":1358,"title":"Wrong interest calculation in `InterestModule`","author":"tedox"},{"number":1364,"title":"Interest Model Logic Bug Causes Yield Leakage","author":"d33p"},{"number":1386,"title":"Borrow rate floor decay under-accrues interest","author":"Sparrow_Jac"},{"number":1391,"title":"Unit mismatch in interest calculation\u00a0when rate decays to\u00a0minimum rate","author":"touristS"},{"number":1392,"title":"Interest Under-Accrual Due to Missing Scaling Factor in Rate Floor Decay Branch","author":"00001111"},{"number":1413,"title":"Undercharged interest when borrow rate decays to MIN_RATE (unit mismatch)","author":"0xeix"},{"number":1416,"title":"The protocol updates totalPaidDebt using the incorrect formula (accruing too little interest)","author":"BroRUok"},{"number":1477,"title":"Protocol will lose ~97% of interest fees when borrow rate decays to MIN_RATE","author":"JeRRy0422"}]},{"severity":"Medium","reward":5.200879009991745,"issues":[{"number":62,"title":"Interest Accrual Denial of Service via Silent Failure","author":"4vian"},{"number":97,"title":"Prolonged inactivity will cause permanent denial of service for interest accrual","author":"fullstop"},{"number":98,"title":"Permanent Interest Disablement Results in Unlimited Interest-Free Borrowing and Protocol-Wide Revenue Collapse","author":"Ba17"},{"number":129,"title":"Long inactivity can freeze interest accrual","author":"heavyw8t"},{"number":182,"title":"Permanent Interest Freeze via Exponential Decay Domain Violation","author":"Edoscoba"},{"number":186,"title":"Prolonged inactivity will permanently freeze interest accrual for Protocol and Vault Stakers","author":"flora2627"},{"number":266,"title":"Incorrect high-utilization decay handling causes perpetual accrual failure on InterestModel.calculateInterest","author":"HeckerTrieuTien"},{"number":321,"title":"Division by zero in InterestModel causes accrual freeze and ERC4626 share inflation","author":"itsgreg"},{"number":327,"title":"`InterestModel::calculateInterest` can revert due to division by 0 and block accruals","author":"tedox"},{"number":359,"title":"Borrowers will halt interest accrual and starve stakers/protocol","author":"neeloy"},{"number":392,"title":"Long Inactivity Permanently Freezes Interest Accrual","author":"bratwork"},{"number":501,"title":"Borrowers will avoid paying interest permanently after 60 days of protocol inactivity","author":"arunabha003"},{"number":587,"title":"Interest Accrual Permanently Stalls due to wadExp Underflow and Missing State Update","author":"0xMosh"},{"number":604,"title":"division by zero DoS when interest rate increases after extended inactivity","author":"blockace"},{"number":694,"title":"Interest accrual can freeze via `wadExp()` returning 0 when calculating `growthDecay` if interest has not been accrued for a sufficiently long timedelta","author":"deadmanwalking"},{"number":718,"title":"Interest accrual bricks forever after long idle periods","author":"cyberEth"},{"number":743,"title":"`wadExp` underflow will permanently freeze Lender contract for all users","author":"0xSpider_Raphl"},{"number":778,"title":"interest accrual freezes permanently when `wadExp()` returns zero due to large inactivity period","author":"MissDida"},{"number":807,"title":"Long inactivity may cause interest accrual to halt due to division by zero","author":"Proof-of-Spirit"},{"number":861,"title":"Division by zero in InterestModel will permanently freeze interest accrual for lenders and protocol","author":"Cryptek_Megatron"},{"number":873,"title":"Interest calculation will cause permanent DoS after extended inactivity","author":"cosin3"},{"number":879,"title":"Interest Rate Model Division by Zero DoS","author":"Sir_Shades"},{"number":891,"title":"`wadExp` Underflow Causes Division by Zero and Silent Interest Accrual Failure","author":"dic0de"},{"number":927,"title":"Interest accrual repeatedly fails after long inactivity when free debt ratio stays below start target","author":"emmanuel_ewah"},{"number":961,"title":"growthDecay could be zero","author":"future"},{"number":1052,"title":"Interest accrual can be permanently frozen via wadExp underflow","author":"0xnija"},{"number":1070,"title":"Protocol will not accrue interest when time elapsed is more than 30 days","author":"copperscrewer"},{"number":1100,"title":"Interest accrual can be skipped after extended market inactivity, allowing borrowers to avoid interest payments","author":"algiz"},{"number":1109,"title":"Interest Model Freeze","author":"vivekd"},{"number":1167,"title":"Permanent interest accrual freeze when `_expRate \u00d7 timeElapsed` hits `wadExp` underflow","author":"0xShoonya"},{"number":1202,"title":"Interest accrual can get stuck when `wadExp()` underflows to 0 causing division-by-zero","author":"xiaoming90"},{"number":1278,"title":"Interest Accrual Stalls for some time period when growthDecay Becomes Zero in condition when rate should increase","author":"0xlucky"},{"number":1406,"title":"Interest Accrual Freeze due to Growth Decay Underflow","author":"Yuubee"},{"number":1426,"title":"Division by zero in \"low free debt ratio\" branch can permanently freeze interest accrual","author":"0xeix"},{"number":1442,"title":"growthDecay can drop to 0 which will DOS the entire contract due to division by 0","author":"slowpoke"},{"number":1443,"title":"Protocol enters permanent frozen state after 30 days of inactivity","author":"teoslaf1"},{"number":1488,"title":"`InterestModel.calculateInterest()` can divide by zero when `wadExp()` underflows to 0, causing persistent interest-accrual failure","author":"JohnWeb3"}]},{"severity":"Invalid","reward":null,"issues":[{"number":5,"title":"setRedemptionStatus can cause underflow when switching to redeemable status","author":"0xsupremedev"},{"number":7,"title":"Zero Price or Oracle Failure Prevents Bad Debt WriteOff, Enabling Protocol Insolvency","author":"bratwork"},{"number":8,"title":"Borrowers will lock collateral for the Protocol","author":"0xSpider_Raphl"},{"number":16,"title":"Redemption fee is incorrectly credited to the borrower, creating an arbitrage opportunity where borrowers profit from being redeemed","author":"jacal"},{"number":17,"title":"First depositor vault share inflation attack allows stealing of subsequent deposits","author":"0xsupremedev"},{"number":20,"title":"Balance Manipulation in Interest Accrual Function","author":"Immanux"},{"number":21,"title":"State update after external call in liquidate allows stealing collateral","author":"Wojack"},{"number":22,"title":"First Deposit MEV Attack Enables Vault Share Theft and ERC4626 Spec Violation","author":"Minion"},{"number":23,"title":"ERC4626 maxDeposit() maxMint() Violate Standard By Returning Unlimited Instead Of Actual Limits","author":"0xheartcode"},{"number":24,"title":"Insufficient Liquidation Incentive Calculation in `Lender::getLiquidatableDebt` and `Lender::getLiquidationIncentiveBps`","author":"AlexScherbatyuk"},{"number":25,"title":"Delegation redirects proceeds to `caller` instead of `borrower`","author":"R.Kundan"},{"number":28,"title":"Fee-on-transfer/rebasing assets let borrowers/PSM users mint unbacked Coin","author":"bratwork"},{"number":29,"title":"Trusting ERC-4626 view methods (previewRedeem) allows accounting inflation `src/Lender.sol`","author":"AlexScherbatyuk"},{"number":31,"title":"`Lender.buy()` Mints Unbacked Coins When Integrated with Fee-Charging ERC4626 Vaults, Leading to Protocol Insolvency","author":"Wojack"},{"number":33,"title":"Precision loss in redeem() allows draining redeemable collateral below nonRedeemableCollateral","author":"0xsupremedev"},{"number":34,"title":"First Depositor Will Lose All Deposited Funds When Depositing Exactly MIN_SHARES Due to ERC4626 Violation","author":"ibrahimatix0x01"},{"number":39,"title":"getPendingInterest() Silent Failures Leads to ERC-4626 MUST Violation","author":"0xheartcode"},{"number":42,"title":"Interest accrual silently fails on external call failure, leading to interest double-counting","author":"0xsupremedev"},{"number":43,"title":"Borrowers will capture accrued interest and erase vault staker yield","author":"mrdafidi"},{"number":44,"title":"Epoch transitions will cause accounting inconsistency between total and individual debt shares","author":"hothacker"},{"number":47,"title":"PSM Buy Fee Drops to 0% after Immutability Deadline","author":"4vian"},{"number":48,"title":"Liquidation function will transfer collateral before receiving payment from liquidators","author":"hothacker"},{"number":50,"title":"Stale oracle allows redemptions at artificially deflated prices causing protocol losses","author":"anchabadze"},{"number":52,"title":"Decimal rounding will cause precision loss for users","author":"hothacker"},{"number":53,"title":"Reentrancy Vulnerability in sell() Function: State Update After External Call Violates Checks-Effects-Interactions Pattern","author":"Sai501"},{"number":54,"title":"Vault Deposit Function Misreports Minted Shares, Breaking ERC4626 Compliance","author":"watsonclyde"},{"number":55,"title":"writeOff condition is strictly impossible for most bad debt scenarios, leading to permanent protocol insolvency","author":"abdul171"},{"number":56,"title":"PSM Vault Share Price Manipulation in buy() Function - Incorrect freePsmAssets Tracking","author":"Sai501"},{"number":58,"title":"H-01: Vault initialization will fail for low-decimal tokens preventing protocol usage","author":"Albert_Mei"},{"number":61,"title":"Liquidation incentives will fail to clear insolvent positions for Lenders/Protocol as Liquidators will suffer a guaranteed loss","author":"Merlinsan"},{"number":64,"title":"Mint function allows first depositor to bypass `MIN_SHARES` requirement","author":"Razkky"},{"number":65,"title":"Division before multiplication in getRedeemAmountOut causes precision loss","author":"0xsupremedev"},{"number":66,"title":"Unrestricted burn() Function Breaks Debt-Supply Accounting Invariant","author":"Sir_Shades"},{"number":67,"title":"Public CREATE3 Deployers Allow Permanent DoS of All Market Deployments","author":"pecata17107"},{"number":70,"title":"The `Coin::burn` function missis the zero value check in burn function, allowing gas wasting.","author":"AlexScherbatyuk"},{"number":72,"title":"First depositor in PSM via\u00a0`buy`\u00a0can be victim of ERC4626 inflation attack, or the Protocol itself can be attacked if it holds shares","author":"jacal"},{"number":74,"title":"Integer division will cause precision loss for depositors","author":"hothacker"},{"number":76,"title":"Any Actor Can Drain All Collateral in the Lender by Triggering Oracle Failure","author":"0_Bash"},{"number":77,"title":"First-Deposit Inflation Protection Is Incomplete, Allowing Zero-Share Mints and Tiny Inflation Attacks in `Vault.sol`","author":"0xMehediSec"},{"number":78,"title":"First depositor will drain prefunded vault assets from treasury seeders","author":"mrdafidi"},{"number":85,"title":"Insolvency Gap: Undercollateralized Positions Cannot be Liquidated or Written Off","author":"bratwork"},{"number":86,"title":"Rounding inconsistencies will cause accounting errors for PSM users","author":"hothacker"},{"number":90,"title":"Missing Stale Price Check in `Lender::getFeedPrice()` function.","author":"AlexScherbatyuk"},{"number":91,"title":"Factory deployment functions will allow unauthorized contract deployments","author":"hothacker"},{"number":93,"title":"Impossible to process bad debt:\u00a0`writeOff`\u00a0threshold is too high, creating a deadlock where underwater positions cannot be liquidated or written off","author":"jacal"},{"number":94,"title":"Attacker will underprice debt and drain reserves from lenders","author":"mrdafidi"},{"number":96,"title":"Return Value Ignored","author":"fahyvor"},{"number":100,"title":"Unauthenticated third\u2011party deposits can grief borrower positions","author":"R.Kundan"},{"number":101,"title":"Lender.redeem() integer-division epoch check enables unbounded multi-epoch transitions causing permanent free-debt borrower DoS via updateBorrower() iteration cap breach","author":"boodieboodieboo"},{"number":103,"title":"Lender.setRedemptionStatus() applies nonRedeemableCollateral adjustment post-updateBorrower() enabling accounting deficit creation via pending redemption timing exploitation","author":"boodieboodieboo"},{"number":110,"title":"Users will be unable to fully clear all free debt via redemption mechanism","author":"flora2627"},{"number":113,"title":"Borrowers partially repaying debt will unfairly reduce the debt of other borrowers and protocol reserves","author":"cmds"},{"number":118,"title":"Incorrect implementation in `Factory.getFeeOf` causing the inability to set a 0% rate for a specific Lender.","author":"0xsolisec"},{"number":119,"title":"Global minimum debt floor not enforced on lender deployment","author":"R.Kundan"},{"number":120,"title":"Interest Accrual Can Be Permanently Disabled When `expRate = 0`, Allowing Borrowers to Avoid Paying Interest Forever","author":"attacker_code"},{"number":133,"title":"`Lender.sell` DoS With Cooldown-Enabled ERC4626 Vaults (e.g., sUSDe) Prevents Asset Redemption","author":"Wojack"},{"number":134,"title":"Attacker will steal funds from the protocol by exploiting rounding errors in debt share calculations","author":"tonnero234"},{"number":136,"title":"Collateral Withdrawal Bug Causes Loss of Fund for Non-18-Decimal Tokens","author":"Lamsya"},{"number":137,"title":"Coin Inflation via Untracked PSM Vault Withdrawal Fees","author":"ibrahimatix0x01"},{"number":138,"title":"Malicious Parameters Allow Scam Protocol Deployment via Factory","author":"EtherEngineer"},{"number":147,"title":"Divergence of `previewDeposit` and `deposit` on first deposit causes underflow and violation of ERC\u20114626 specification because `MIN_SHARES` is truncated twice","author":"JuggerNaut"},{"number":150,"title":"`Vault.sol` violates ERC4626 MUST requirement","author":"tedox"},{"number":151,"title":"Burning `MIN_SHARES` in Vault is done by modifying `balanceOf` directly without reducing `totalSupply` which violates ERC20 and ERC4626 invariants","author":"JuggerNaut"},{"number":153,"title":"Bypass Interest Rate Policy through `freePsmAssets` Manipulation","author":"JuggerNaut"},{"number":154,"title":"Desynchronization of Collateral Accounting causes Invariant Failure due to Sporadic Redemption Updates","author":"desaperh"},{"number":157,"title":"User will lose deposited collateral when withdrawing the same amount","author":"0xkb"},{"number":160,"title":"First depositor loses MIN_SHARES when calling Vault::deposit()  (inconsistent handling vs mint())","author":"3rdeye"},{"number":162,"title":"Various in-compliance with ERC4626","author":"y4y"},{"number":166,"title":"InterestModel will severely under-accrue interest for lenders during exponential rate growth due to truncating integer division","author":"watsonclyde"},{"number":167,"title":"H-03: Stale oracle `reduceOnly` mode will prevent borrowers from managing risk, potentially forcing liquidations or trapping funds","author":"Albert_Mei"},{"number":171,"title":"`accruePsmProfit` may lead to unbacked Coin minting.","author":"y4y"},{"number":172,"title":"Value Returned is Ignored","author":"fahyvor"},{"number":177,"title":"PSM Vault Deposit Fees Allow Operator to Mint Unbacked Stablecoins and Extract User Funds","author":"jayjoshix"},{"number":178,"title":"PSM users will suffer permanent loss of funds due to stuck reserves","author":"0xDyDx"},{"number":180,"title":"First Vault deposit event will over-credit shares for the first depositor","author":"manvita836"},{"number":189,"title":"removing collateral can put system in inconstant state for borrower, and borrower get nothing as collateral","author":"GaurangBrdv"},{"number":190,"title":"Malicious User will permanently disable PSM sell functionality for Protocol Users","author":"flora2627"},{"number":193,"title":"Interest accrual correctness invariant is broken due to `timeToMin` calculation truncation","author":"bbl4de"},{"number":196,"title":"Delegate can appropriate borrowed funds leading to user debt accumulation and potential loss of collateral","author":"0xkb"},{"number":200,"title":"Integer Division Precision Loss in Interest Calculation at `InterestModel.sol::calculateInterest()`","author":"0xMafiaBug"},{"number":201,"title":"Decaying Interest Calculation Uses Incorrect Division Order in `InterestModel.sol::calculateInterest()`","author":"0xMafiaBug"},{"number":203,"title":"ERC4626 Vault Spec Violation for Small Deposits","author":"Bin-Darweesh"},{"number":204,"title":"Lens.getDebtOf Returns Inconsistent Debt Values","author":"Bin-Darweesh"},{"number":206,"title":"Interest Accrual Stops Completely When Borrow Rate Exceeds Cap","author":"Bin-Darweesh"},{"number":209,"title":"`InterestModel.sol::calculateInterest` Missing 1e18 Scaling Causes Zero Interest Accrual During Rate Adjustments","author":"0xMafiaBug"},{"number":218,"title":"Attacker will drain redeemable collateral without repaying debt protocol and borrowers","author":"zcai"},{"number":220,"title":"Accounting Mismatch in `sell` function","author":"Immanux"},{"number":223,"title":"Delegation Allows Delegatee to Steal Funds","author":"Bin-Darweesh"},{"number":232,"title":"Single Operator Key Controls $2B+ Protocol Infrastructure","author":"deucefury"},{"number":233,"title":"Cross-Chain Infrastructure Fragmentation Enables Selective Exploitation","author":"deucefury"},{"number":235,"title":"Interest Accrual Creates Unminted Debt Leading to Protocol Insolvency","author":"0xMafiaBug"},{"number":236,"title":"Authorization Bypass in adjust() Function Enables Phantom Collateral Injection","author":"deucefury"},{"number":237,"title":"Factory Deployment System Enables Malicious Parameter Injection","author":"deucefury"},{"number":238,"title":"Mathematical Proof of Economic Unsustainability","author":"deucefury"},{"number":240,"title":"Immutability System Enables Permanent Exploitation Parameter Lock-in","author":"deucefury"},{"number":241,"title":"Complete Absence of Security Monitoring Infrastructure","author":"deucefury"},{"number":242,"title":"Single Oracle Dependency Enables $200M+ Manipulation Attacks","author":"deucefury"},{"number":243,"title":"`Lender.buy` creates immediate unbacked debt when integrating ERC4626 Vaults with fees or slippage","author":"ReidnerM"},{"number":247,"title":"Withdrawal is not Compatible with Token Decimals < 18","author":"0xsh"},{"number":248,"title":"First Depositor Creates Permanent ERC-4626 Economic Dilution via Dead-Weight Shares","author":"0xHexed"},{"number":250,"title":"Global Nonce Enables Front\u2011Running and Breaks Deterministic CREATE3 Deployments","author":"rj_eth26"},{"number":251,"title":"Hardcoded MIN_SHARES constant prevents Vault creation for tokens with low decimals (USDC/USDT)","author":"M1troV"},{"number":254,"title":"Malicious User will permanently disable PSM buy functionality for the Protocol","author":"flora2627"},{"number":260,"title":"`maxDeposit()` and `maxMint()` violate ERC4626 standard due to MIN_SHARES requirement","author":"magickenn"},{"number":261,"title":"Attacker can mint Coin while vault is below the configured minimum on `Lender.buy`","author":"HeckerTrieuTien"},{"number":262,"title":"Division by Zero After State Modification Creates  Denial of Service in Core Redemption Mechanism","author":"frankauditcraft"},{"number":263,"title":"Liquidator-borrower can siphon repaid debt from other borrowers on `Lender.decreaseDebt`","author":"HeckerTrieuTien"},{"number":267,"title":"Attacker can Drain Redeemable Collateral Through `buy`/`redeem`","author":"HeckerTrieuTien"},{"number":268,"title":"Malicious depositor can drain pre-seeded assets from vault on `deposit`","author":"HeckerTrieuTien"},{"number":269,"title":"First depositors pay a 1e16 share 'tax' that disproportionately impacts small deposits","author":"Protokol"},{"number":273,"title":"Malicious Borrower will steal Collateral from Protocol","author":"Smacaud"},{"number":275,"title":"Attacker will cause Permanent Insolvency","author":"Smacaud"},{"number":279,"title":"ERC-4626 Violation: previewDeposit Returns `0` for Failing Deposits","author":"Immanux"},{"number":280,"title":"ERC-4626 Violation: maxDeposit Returns `type(uint256).max (unlimited)`  When First Deposits Will Revert","author":"Immanux"},{"number":281,"title":"getPendingInterest() Returns Incorrect Value","author":"SnowX"},{"number":288,"title":"Debt Share Price Erosion via Asymmetric Rounding","author":"SnowX"},{"number":290,"title":"Any user will seize residual collateral and socialize bad debt for all borrowers","author":"R.Kundan"},{"number":293,"title":"Unchecked withdraw-fee in `Lender.sell()` causes PSM accounting drift and potential sell DoS","author":"zubyoz"},{"number":294,"title":"PSM uses `previewRedeem` for accounting instead of actual balance, creating phantom assets that lead to protocol insolvency","author":"hodlturk"},{"number":295,"title":"First deposit violates ERC-4626 MUST-rules by creating phantom supply and breaking share\u2013asset proportionality","author":"theholymarvycodes"},{"number":297,"title":"Core protocol invariant is broken","author":"dimulski"},{"number":298,"title":"Protocol interest rate calculation can be manipulated through debt inflation by attacker who manufactures bad debt while being a vault staker","author":"TOSHI"},{"number":300,"title":"ERC4626 Gas Trap Violation","author":"SnowX"},{"number":302,"title":"PSM fee drift allows protocol insolvency through accounting mismatch","author":"SnowX"},{"number":304,"title":"Decimal truncation in collateralToInternal() causes permanent user fund loss","author":"SnowX"},{"number":307,"title":"ERC4626 Compliance Violation: previewMint() Returns Incorrect Asset Cost, Causing First Minters to Overpay by MIN_SHARES","author":"frankauditcraft"},{"number":311,"title":"Anyone can withdraw collateral from a borrower's bad debt.","author":"leopoldflint"},{"number":312,"title":"ERC4626 vault fees will cause PSM to mint unbacked coin","author":"zcai"},{"number":314,"title":"Share Price Invariant Violation via Rounding Down in `decreaseDebt()` Allows Debt Reduction Without Share Burn","author":"0xb0k0"},{"number":315,"title":"Factory Missing Deployment Validation - No Code Length Checks Before/After CREATE3 Deployment","author":"Sai501"},{"number":316,"title":"First Depositor Inflation Attack on Vault","author":"kkkkkk"},{"number":317,"title":"Debt positions can still be liquidated in case oracle price is stale and after unwind duration","author":"0xc0ffEE"},{"number":318,"title":"First Borrower Inflation Attack on Lender","author":"kkkkkk"},{"number":320,"title":"ERC-4626 Violations in Vault Contract","author":"jo13"},{"number":322,"title":"Per-epoch free-debt share shrink 1->0 erases debt enabling collateral and PSM reserve drain","author":"itsgreg"},{"number":323,"title":"Oracle Stale Mode Prevents Zero-Debt Withdrawals","author":"kkkkkk"},{"number":326,"title":"Ownerless interest mint combined with PSM convertibility enables zero-capital drain of protocol reserves","author":"itsgreg"},{"number":328,"title":"Liquidation Creates Accounting Mismatch","author":"kkkkkk"},{"number":330,"title":"`previewDeposit` is Misleading and Breaks ERC-4626 Composability for First Deposit","author":"cosminm53"},{"number":331,"title":"CREATE3 Deployment Front-Running DoS","author":"kkkkkk"},{"number":332,"title":"Factory Missing Parameter Validation","author":"kkkkkk"},{"number":333,"title":"Users can bypass minimum debt requirements","author":"zcai"},{"number":336,"title":"External failures will cause protocol invariant breakdown during liquidations","author":"mishoko"},{"number":337,"title":"Vault totalAssets() Includes Unaccrued Interest - MEV Sandwich Attack","author":"kkkkkk"},{"number":339,"title":"Withdrawal Precision Loss Accumulates","author":"kkkkkk"},{"number":341,"title":"Stale freePsmAssets do not reflect psm vault profits/losses leaving interest rates stale","author":"algiz"},{"number":342,"title":"Vault is not strictly ERC4626 Compliant as it should be","author":"0xpoison"},{"number":343,"title":"Value incorrect redemption logic causes free debt borrowers to lose collateral when collateral price exceeds stablecoin price","author":"Shalala"},{"number":344,"title":"Un-sellable psm backed coins due to accounting denomination mismatch in ```freePsmAssets```.","author":"asui"},{"number":347,"title":"Protocol Will Accrue Bad Debt Due To Liquidation Design","author":"0xSomeHuntoor"},{"number":352,"title":"```Buy``` function allows users to mint unbacked coins for psmVaults with deposit fees.","author":"asui"},{"number":358,"title":"Liquidator will steal written-off collateral from borrowers","author":"neeloy"},{"number":362,"title":"Share Deflation Mismatch Creates Orphaned Debt","author":"0x97"},{"number":364,"title":"Vault First Deposit Underflow Permanently Bricks Protocol","author":"0x97"},{"number":367,"title":"Oracle Price Manipulation via Mempool Frontrunning","author":"0x97"},{"number":368,"title":"First-Deposit Sandwich Attack Enables Yield Theft","author":"m4ze"},{"number":369,"title":"Gas Griefing in accrueInterest Allows Interest Skipping","author":"m4ze"},{"number":370,"title":"Vault First Deposit Inconsistency (MIN_SHARES Logic Mismatch)","author":"m4ze"},{"number":373,"title":"PSM Vault Yield Desynchronization Causes Underflow","author":"m4ze"},{"number":374,"title":"Borrowers will exploit invalid oracle price defaulting to prevent liquidations and manipulate solvency calculations","author":"m3dython"},{"number":375,"title":"Asset Burning via Withdraw/Redeem to address(0)","author":"m4ze"},{"number":376,"title":"PSM Vault Deposit Inflation for Premium Selling","author":"m4ze"},{"number":378,"title":"The buy function will Mint Unbacked Coins Breaking 1:1 Backing for Coin Holders","author":"m3dython"},{"number":380,"title":"Borrowers will benefit from underestimated debt calculations affecting lenders and stakers","author":"m3dython"},{"number":382,"title":"Borrowers will repay less debt than owed due to stale debt calculations in Lens._getSyncedTotalDebt","author":"m3dython"},{"number":383,"title":"Lender Contract Will Cause Denial of Service to Vault Users","author":"m3dython"},{"number":385,"title":"PSM Buy Path Can Under Collateralize the System When Vaults Apply Deposit Fees","author":"x0lohaclohell"},{"number":389,"title":"Vault deposit() Can Mint Zero Shares After MIN_SHARES Deduction - Direct Fund Loss","author":"Sai501"},{"number":390,"title":"PSM `buy` Logic Ignores Vault Deposit Fees/Slippage, Leading to Insolvency","author":"bratwork"},{"number":394,"title":"Universal Staleness Threshold Forces Acceptance of Stale Data Due to USDC/USD's 24-Hour Heartbeat","author":"Wolf_Kalp"},{"number":395,"title":"Vault Freezing via Unprotected accrueInterest","author":"richi"},{"number":398,"title":"Vault Pending Interest Sandwich Attack","author":"richi"},{"number":399,"title":"nonRedeemableCollateral Accounting Desync","author":"richi"},{"number":400,"title":"Liquidation Front-Running and Griefing","author":"richi"},{"number":401,"title":"[MEDIUM] Stale oracle causes global, persistent DoS of Coin redemptions for free\u2011debt lenders","author":"Draxen"},{"number":402,"title":"Over-Accrual of Interest in Rate Decay Calculation","author":"ChainProof"},{"number":403,"title":"Ineffective Precision Handling in Epoch Reset Leads to Permanent Ledger Inflation","author":"fullstop"},{"number":405,"title":"`Vault::deposit` violate EIP-4626 MUST when `isFirstDeposit` is true","author":"farismaulana"},{"number":410,"title":"Missing `MIN_RATE` enforcement in multiple Interest calculations Branches","author":"securehash1"},{"number":413,"title":"practice of crediting `MIN_SHARES` to `address(0)` on the very first deposit will cause a lasting mis-pricing of shares","author":"jo13"},{"number":414,"title":"Mismatch in collateral Withdrawal due to Decimal Conversion Rounding","author":"securehash1"},{"number":418,"title":"ERC4626 Violation `deposit` vault","author":"nodesemesta"},{"number":421,"title":"Arithmetic precision loss will cause yield leakage for Lenders","author":"tonnero234"},{"number":426,"title":"MIN_LIQUIDATION_DEBT of $10,000 is 5x higher than industry standards causing forced over-liquidations","author":"anchabadze"},{"number":427,"title":"Underflow in bad debt socialization can unfairly shift full burden to paid debt borrowers","author":"X0sauce"},{"number":428,"title":"Missing Borrower State Update in Redeem Function","author":"securehash1"},{"number":430,"title":"PSM deposits inflate free\u2011debt ratio and depress borrow rate (economic rate manipulation)","author":"zubyoz"},{"number":432,"title":"Incorrect Debt Calculation for Users with Missed Epochs","author":"securehash1"},{"number":433,"title":"Liquidation leaves behind dust debt that cannot be incentivly cleared","author":"X0sauce"},{"number":439,"title":"MEV bots will extract value from depositors by manipulating interest accrual timing through ERC4626 preview/execution inconsistency","author":"TOSHI"},{"number":442,"title":"Liquidations increases position's LTV and may lead to bad debt accumulation","author":"AlexCzm"},{"number":444,"title":"PSM Vault Share Rounding Causes Unbacked Coin Minting and Protocol Insolvency","author":"OxNoble"},{"number":447,"title":"Malicious or compromised `factory` can drain all global reserves by injecting arbitrary fee via `getFeeOf()` and minting protocol-backed `coin`","author":"OCC"},{"number":454,"title":"Logic error in `getFeeOf` will prevent setting 0% fees for Lenders","author":"tonnero234"},{"number":455,"title":"Epoch Transitions Permanently Wipe Small Free Debt Positions Below 1e18 Shares","author":"maxim371"},{"number":457,"title":"Rounding Errors Cause Debt Increase When Users Switch Redemption Status","author":"maxim371"},{"number":458,"title":"Operator Can Mint Unbacked Coin and Steal User Funds by Bypassing `psmAsset` Validation","author":"farismaulana"},{"number":461,"title":"Excessive collateral seizure due to stale debt used in incentive calculation leads to bad debt","author":"Shalala"},{"number":464,"title":"Unbacked Minting via ERC4626 Inflation Attack causes Protocol Insolvency","author":"fullstop"},{"number":473,"title":"Extremely high writeOff threshold of 100:1 creates massive bad debt accumulation zone","author":"anchabadze"},{"number":474,"title":"Underwater liquidation bonus enlarges bad debt for all borrowers","author":"cheng"},{"number":476,"title":"Division by Zero Prevents Full Redemption of Free Debt","author":"Lamsya"},{"number":478,"title":"Rounding Direction Error in Lender.sell Causes User Fund Loss and Protocol Accounting Imbalance","author":"fullstop"},{"number":479,"title":"Collateral Cache Poisoning Attack","author":"mishoko"},{"number":480,"title":"Vault First Deposit MIN_SHARES Underflow / ERC\u20114626 Non-Compliance","author":"g93m"},{"number":482,"title":"Incorrect Use of previewRedeem for Liquidity Accounting Causes DoS When Underlying ERC-4626 Vault Is Paused or Withdraw-Limited","author":"yoooo"},{"number":483,"title":"Missing Decimal Conversion on Collateral Withdrawal Causes 100% Loss of User Funds","author":"0xpoison"},{"number":485,"title":"Return Value Ignored","author":"fahyvor"},{"number":486,"title":"Vault\u2019s MIN_SHARES misaccounting lets attacker extract value from all future users","author":"Rocky_14"},{"number":487,"title":"Title Vault Deposit Without Accrued Interest Steals Pending Yield","author":"g93m"},{"number":490,"title":"Value Returned is Ignored","author":"fahyvor"},{"number":491,"title":"Liquidation reward calculation creates arbitrage opportunity for self-liquidation","author":"cheng"},{"number":492,"title":"Unchecked User Input in Adjust Function Leading to Arithmetic Overflow/Underflow","author":"snufflesrea"},{"number":493,"title":"PSM seller will brick redemptions and leave PSM-backed Coin supply under-backed","author":"neeloy"},{"number":497,"title":"Fee-on-transfer PSM tokens will cause protocol insolvency as buy() mints unbacked COIN","author":"joshuam33"},{"number":498,"title":"Off-chain integrators will misprice collateral and misjudge borrower solvency due to the hardcoded 18-decimal normalization in Lender.getFeedPrice()","author":"0x_oi"},{"number":500,"title":"First PSM user will be permanently DOSed when vault starts empty","author":"arunabha003"},{"number":502,"title":"Silent Interest Accrual Failure Enables Debt Undertracking","author":"EtherEngineer"},{"number":503,"title":"Borrowers will suffer systematic collateral loss due to rounding deficit in redemption distribution","author":"0xleo"},{"number":504,"title":"Liquidation Gas Check Vulnerable to EIP-150 Rule Allows Skipping Bad Debt Writeoff","author":"maxim371"},{"number":507,"title":"Stale Debt Share Invariant Violation in `Lender::setRedemptionStatus` Allows Non-Redeemable Users to Retain Free Debt Shares","author":"Fjor1025"},{"number":511,"title":"Stale Debt Share Invariant Violation in `Lender::adjust(bool)` Allows Non-Redeemable Users to Retain Free Debt Shares","author":"Fjor1025"},{"number":514,"title":"PSM depositor will DoS `sell()` redemptions for PSM-backed Coin holders","author":"neeloy"},{"number":517,"title":"Borrower will drain collateral from other redeemable borrowers","author":"neeloy"},{"number":518,"title":"Missing Explicit Return in getPendingInterest() Catch Block Enables Share Price Manipulation","author":"maxim371"},{"number":520,"title":"Sell-Side Fee Is Not Applied in Non-ERC4626 PSM Deployments","author":"3rdeye"},{"number":522,"title":"H-01 - Epoch Transition Manipulation","author":"0xNihilo"},{"number":524,"title":"M-01 - PSM Sandwich Attack","author":"0xNihilo"},{"number":525,"title":"M-02 - Rounding Asymmetry","author":"0xNihilo"},{"number":526,"title":"M-03 - Gas Griefing","author":"0xNihilo"},{"number":528,"title":"Vault Initialization Breaks ERC-4626 First-Deposit Invariants","author":"g93m"},{"number":529,"title":"Incentivized Partial Liquidation of Insolvent Positions Widen Protocol Deficit, Degrades Borrower Health, and Dilutes Lender Value via Delayed Write-Offs","author":"theboiledcorn"},{"number":531,"title":"Epoch Compression Rounding Asymmetry","author":"SnowX"},{"number":532,"title":"Users may not be able to redeem their collateral due to improper handling when collateralToken has 6 decimals.","author":"MoZi"},{"number":533,"title":"Lack of decimal scaling in share calculation renders the vaults useless for USDC and USDT markets due to impossible initialization cost","author":"Silverwind"},{"number":535,"title":"Borrower can avoid interest payments, causing loss for protocol free debt borrowers, staker yield leading to bad debts","author":"0xkb"},{"number":543,"title":"Mint Function Emits Incorrect Share Amount in Deposit Event on Initial Deposit - EIP VIOLATION","author":"0xBoraichoT"},{"number":544,"title":"Operator Fee Extraction via Parameter Manipulation","author":"SnowX"},{"number":546,"title":"Socialized Bad Debt redistribution causes instantaneous insolvency for innocent borrowers","author":"oxGan1"},{"number":549,"title":"Vault: incorrect MIN_SHARES handling leading to phantom shares, event/state mismatch, and underflow","author":"Xmanuel"},{"number":554,"title":"Redemption fees are not accrued to protocol reserves","author":"0xsai"},{"number":555,"title":"`liquidate()` computes liquidation incentive using stale pre-repayment debt, overpaying liquidators even when the position becomes solvent after repayment","author":"legat"},{"number":559,"title":"Reduce-only bypass via redemption status flip (debt migration without policy/solvency checks)","author":"rj_eth26"},{"number":560,"title":"Using `previewRedeem()` instead of `convertToAssets()` when accounting for deposited shares leads to incorrect `freePsmAssets` tracking and withdrawal failures","author":"dobrevaleri"},{"number":563,"title":"Rounding error in ERC4626 vault deposit could lead to breaking PSM reserves invariant and potential fund lock","author":"dobrevaleri"},{"number":565,"title":"Arithmetic Overflow In InterestModel using Simple Interest calculation","author":"0xfallin1"},{"number":570,"title":"Buy and sell functions incorrectly handle rebasing PSM assets by tracking parameter values instead of actual transferred amounts","author":"anchabadze"},{"number":572,"title":"H-01: Epoch Skipping allows borrowers to avoid accumulated redemption fees","author":"0xsupremedev"},{"number":578,"title":"PSM sell() inflates freePsmAssets by expected amount instead of actual redemption","author":"vivekd"},{"number":583,"title":"Liquidation rounding desync causes phantom collateral loss and accounting divergence","author":"rj_eth26"},{"number":584,"title":"Dust shares cause massive integer overflow in redemption tracking corrupting borrower collateral balances","author":"0xzulkifilu"},{"number":589,"title":"Incompatibility with cooldown-enabled ERC-4626 vaults like sUSDe causes permanent DoS in PSM redemptions","author":"0xShoonya"},{"number":590,"title":"PSM Vault Accounting Drift in sell()","author":"0xMosh"},{"number":591,"title":"Bad debt can accumulate at certain point where there is no more liquidation incentive.","author":"Flashloan44"},{"number":592,"title":"Incorrect collateral scaling in withdrawal logic leads to stuck user funds for non-18 decimal tokens","author":"0xShoonya"},{"number":600,"title":"PSM buy() guard blocks replenishment once psmVault.totalSupply() hits minTotalSupply","author":"vivekd"},{"number":607,"title":"liquidation always causes loss for small debt positions due to MIN_LIQUIDATION_DEBT logic flaw","author":"blockace"},{"number":617,"title":"Liquidation incentive calculated with stale debt allows repeated liquidations","author":"blockace"},{"number":618,"title":"updateBorrower() shrinks a borrower\u2019s freeDebtShares across epochs but does not update totalFreeDebtShares; breaks the global shares invariant and enables a practical DoS / accounting corruption.","author":"Xmanuel"},{"number":622,"title":"First depositor manipulates PSM vault share ratio to steal half of users deposits","author":"0xzulkifilu"},{"number":624,"title":"a very severe design inconsistency","author":"songyuqi"},{"number":627,"title":"Borrowers can extract collateral at discounted price through liquidation leaving protocol bad debt","author":"blockace"},{"number":628,"title":"Deployments through the Factory can always get DOS'd","author":"Kalogerone"},{"number":631,"title":"Selling fee is missing leading to protocol losses","author":"0xeix"},{"number":632,"title":"The remaining collateral is not distributed during write off, but transferred to the caller","author":"joshuajee"},{"number":637,"title":"`previewDeposit()` violates EIP-4626 specification by returning incorrect shares when assets are below minimum","author":"cheng"},{"number":639,"title":"neglected bad debt would cause the whole contract bricked and users collateral loss","author":"farismaulana"},{"number":642,"title":"Borrowers selling coin for psm assets can break psm backing guarantees","author":"X0sauce"},{"number":644,"title":"Retroactive Yield Capture via Donation Steals Protocol Reserve Revenue","author":"jayjoshix"},{"number":647,"title":"minDebt is not checked when adjust position","author":"coffiasd"},{"number":654,"title":"Redeemable borrowers suffer information asymmetry due to delayed collateral updates","author":"SnowX"},{"number":658,"title":"PSM ERC4626 vault buys mint underbacked Coin when share price != 1","author":"vivekd"},{"number":659,"title":"First sellers will cause insolvency for remaining PSM users","author":"eloujoe"},{"number":664,"title":"Missing `accruePsmProfit` call in `pullGlobalReserves` results in uncollected yield","author":"oxGan1"},{"number":667,"title":"Malicious collateral token will corrupt collateral accounting for all borrowers","author":"Rocky_14"},{"number":668,"title":"Attacker will steal non-redeemable borrowers' collateral through flash loan manipulation of balance checks violating protocol's core protection guarantee","author":"0xzulkifilu"},{"number":672,"title":"Lender.acceptOperator() leaves pendingOperator uncleared, causing stale privileged state","author":"Rocky_14"},{"number":673,"title":"`setRedemptionStatus()` allows borrower to hold debt below `minDebt`","author":"0xnightswatch"},{"number":677,"title":"The MIN_SHARES value is too large and many tokens won't be supported including USDC, USDT & WBTC","author":"joshuajee"},{"number":679,"title":"Arbitrary Write-Off Threshold Prevents Socialization of Bad Debt","author":"Meoww"},{"number":680,"title":"accrueInterest() silently skips interest accrual based on gas checks, causing accounting divergence","author":"Rocky_14"},{"number":681,"title":"Operators will charge global fees instead of zero when setting custom fee to zero for specific lenders","author":"Meoww"},{"number":687,"title":"Deployer can set a custome price feed that he can control","author":"Valves"},{"number":690,"title":"Deployer can set psmVault to a vault that he controls and steal all user funds","author":"Valves"},{"number":692,"title":"Shares are not properly locked when minting first liquidity","author":"joshuajee"},{"number":693,"title":"Extreme Write-Off Threshold Creates Unresolvable Bad Debt Window","author":"0xheartcode"},{"number":695,"title":"Borrower will exit without paying accrued interest harming vault stakers and reserve recipients","author":"0xSam"},{"number":696,"title":"Liquidation Function Fails to Enforce Minimum Liquidation Debt Allowing Griefing and Economic Attacks","author":"0xKann"},{"number":701,"title":"PSM Fee Post Deadline Reset","author":"0xheartcode"},{"number":707,"title":"New free mode borrowers will be charged with redemption amounts since genesis(deployment) because ```updateBorrower``` fails to update the epoch and last redeem index for new entries.","author":"asui"},{"number":709,"title":"Borrowers Can Avoid Paying Interest Indefinitely Through Gas Manipulation","author":"dee_bug"},{"number":710,"title":"The `getFeedPrice()` function doesn't correctly convert the feed's decimals","author":"Kalogerone"},{"number":714,"title":"Broken PSM reserve invariant","author":"tedox"},{"number":716,"title":"Decimals mismatch will result in unlimited borrowing power.","author":"bughuntoor"},{"number":721,"title":"Overrestrictive check unnecessarily distributes Vault yield to the stablecoin operator.","author":"bughuntoor"},{"number":724,"title":"Liquidating a fixed 25% of total debt and not a user-specified amount can be problematic for very large whale positions","author":"deadmanwalking"},{"number":727,"title":"Custom fee overrides can never express 0 bps","author":"cyberEth"},{"number":728,"title":"Fees cannot be changed after immutability deadline, contrary to README","author":"deadmanwalking"},{"number":730,"title":"`writeOff()` Failure Is Silently Ignored","author":"TugayBehat"},{"number":738,"title":"Borrow rate overshoots `MIN_RATE` at decay boundary due to imprecise exponetial transition logic","author":"0xfallin1"},{"number":739,"title":"Permanent User DoS \u2014 Borrower positions become permanently bricked when global epochs exceed 5-epoch update limit","author":"Ba17"},{"number":740,"title":"Small Interest Accrual Leads to internal Accounting mismatch","author":"kowolski"},{"number":741,"title":"PSM deposits register as free debt and flatten borrow rates","author":"cyberEth"},{"number":742,"title":"Tiny Partial Liquidations Enable Near-Free Collateral Drainage and Massive Bad Debt Socialization via Write-Off Mechanism","author":"Macbughunter"},{"number":744,"title":"ERC4626 previews MUST match deposit success, but first deposit always panics","author":"cyberEth"},{"number":745,"title":"Free Debt Share Price Monotonicity Violation Due to Redemptions","author":"molaratai"},{"number":747,"title":"Forced Full Position Liquidation Through PSM","author":"DemiGods"},{"number":748,"title":"Epoch Manipulation Causes Unfair Debt Redistribution for Inactive Borrowers","author":"ubl4nk"},{"number":749,"title":"Repeated Partial Liquidations Enable Collateral Drain and Cascading Insolvency","author":"SOPROBRO"},{"number":752,"title":"Incorrect nonRedeemableCollateral Accounting in writeOff() Causes Protocol Insolvency","author":"ubl4nk"},{"number":753,"title":"Wrong gas requirement statement in `accrueInterest` becasue of the 1/64th rule","author":"4th05"},{"number":755,"title":"The invariant of PSM reserves could be broken","author":"0xpiken"},{"number":757,"title":"previewMint violates EIP specification due to interest accrue logic","author":"0xGondar"},{"number":758,"title":"previewMint violates EIP specification since it can revert","author":"0xGondar"},{"number":759,"title":"Hardcoded `MIN_SHARES` Bricks Vaults for Low-Decimal Assets","author":"befree3x"},{"number":761,"title":"The `Vault` contract `MIN_SHARES` can result in big losses","author":"Kalogerone"},{"number":763,"title":"[H-1] Missing Price Oracle in `accruePsmProfit` function, leads to Critical Miscalculation of `accruedLocalReserves` Value.","author":"chain__warden"},{"number":764,"title":"PSM Reserves Can Be Drained By Non-PSM Backed Stablecoin Supply, Breaking Core Invariant","author":"molaratai"},{"number":765,"title":"Lens Contract Will Falsely Report Debt as Zero to Third-Party Systems","author":"francoHacker"},{"number":767,"title":"[H-2] Missing Price Oracle in `getFreeDebtRatio` function, leads to Critical Miscalculation of `calculateInterest` Values.","author":"chain__warden"},{"number":772,"title":"Unfair Share Distribution in ERC4626 Vault Causes Late Depositors to Subsidize Early Depositors","author":"EtherEngineer"},{"number":773,"title":"Integer Underflow in Interest Calculation During Rate Decay","author":"0x97"},{"number":774,"title":"Integrators will lose funds sent to predicted addresses due to context mismatch in `LenderDeployer`","author":"0xSpider_Raphl"},{"number":775,"title":"Interest Accrual Evasion Through Gas Limit Manipulation Enables Systematic Yield Theft","author":"OxNoble"},{"number":776,"title":"Attacker can mint unlimited debt tokens by desynchronizing debt shares from total debt","author":"firmanregar"},{"number":777,"title":"Interest Accrual Invariant Violation","author":"DevBear0411"},{"number":779,"title":"Liquidation does not make the debt position healthy","author":"Ocean_Sky"},{"number":781,"title":"Redeemable users with zero debt have their collateral exposed to redemptions without corresponding balance reduction","author":"MissDida"},{"number":782,"title":"PSM Reserve Accounting Invariant Violation","author":"DevBear0411"},{"number":783,"title":"PSM Operator Revenue is Distributed to Users During Redemptions","author":"molaratai"},{"number":785,"title":"Lender Constructor Fails to Enforce Documented 6-18 Decimal Requirement for Tokens, Allowing Deployment with Out-of-Spec Tokens","author":"frankauditcraft"},{"number":786,"title":"Operator will trigger rapid interest rate hikes for borrowers","author":"0xSpider_Raphl"},{"number":789,"title":"Share price monotonicity invariant violation","author":"DevBear0411"},{"number":790,"title":"Attacker will  mint extra Coin not backed by PSM assets harming all Coin holders","author":"NovaTheMachine"},{"number":794,"title":"title: share price monotonicity can be violated via normal partial repayment (no `writeOff`)","author":"BroRUok"},{"number":795,"title":"Unfair risk-return mismatch in bad debt allocation","author":"h2134"},{"number":796,"title":"Global Reserves Underfunded When Staking Insufficient","author":"Theseersec"},{"number":798,"title":"Divide-by-Zero in Interest Calculation","author":"DevBear0411"},{"number":801,"title":"Redeemers can freeze borrowers by desynchronizing free debt shares across epochs","author":"Valves"},{"number":806,"title":"Users can't repay the debt if the delegate is changed","author":"0xeix"},{"number":808,"title":"Bad Debt Accumulation When Liquidations Are Disabled Due to Invalid Price Feed","author":"magickenn"},{"number":811,"title":"Missing Solvency Check in setRedemptionStatus Allows Insolvent Positions After Interest Accrual","author":"magickenn"},{"number":812,"title":"No incentive to liquidate debt if `debt == MIN_LIQUIDATION_DEBT`","author":"ck"},{"number":813,"title":"`sell()` function will not work if the asset initially depegs < 1$","author":"0xeix"},{"number":814,"title":"Systematic bad debt generation through liquidation incentives","author":"h2134"},{"number":825,"title":"Operator can interfere with the pricing of `Monolith Coins` contradicting with the expected behaviour.","author":"Aasif"},{"number":830,"title":"WBTC Collateral Is Priced Using BTC/USD Chainlink Feed, Ignoring WBTC Depegging Risk","author":"futureHack"},{"number":834,"title":"Coin Value can be diluted by unaccounted PSM vault fees","author":"h2134"},{"number":836,"title":"Using hardcoded staleness unwind duration with volatile token can cause problems","author":"Aasif"},{"number":837,"title":"Borrowers can self liquidate themselves and put the Lending pool contract at bad debt.","author":"itsabinashb"},{"number":838,"title":"Minimum Debt Constraint Can Prevent Risk-Reducing Repayment","author":"futureHack"},{"number":840,"title":"Decrease in freePsmAssets","author":"future"},{"number":841,"title":"Insufficient freePsmAssets Handling","author":"future"},{"number":843,"title":"Debt Share Price Decrease","author":"future"},{"number":844,"title":"Operator Receives Less PSM Profit","author":"future"},{"number":845,"title":"Interest calculation frequency","author":"future"},{"number":846,"title":"Economic/Incentive Flaw For Stakers due to Aggressive Yield Clipping","author":"Sneks"},{"number":847,"title":"Rate Increase in Decay Regime Breaks Protocol's Economic Signaling","author":"GypsyKing18"},{"number":850,"title":"Users can self liquidate to harm the protocol","author":"ck"},{"number":854,"title":"Collateral Withdrawal Blocked by Stale Oracle Price, preventing Partial Repayment and Withdrawal actions.","author":"Sneks"},{"number":855,"title":"Any external caller can force bad-debt distribution onto borrowers and extract residual collateral from an undercollateralised borrower position via the permissionless Lender.sol::writeOff() function.","author":"Web3Angel"},{"number":856,"title":"Free debt liquidation and coin redemptions can break free debt share price invariant","author":"X0sauce"},{"number":857,"title":"last borrower cant repay their debt because of `MIN_SHARES` worth of Coin is always inside the Vault","author":"farismaulana"},{"number":859,"title":"{User} will {lose tokens} {on small repayments} due to rounding direction","author":"dic0de"},{"number":863,"title":"Borrower Can Frontrun Liquidation by Adding Collateral, Causing Denial of Service","author":"futureHack"},{"number":865,"title":"Reentrancy in liquidate() Allows Permanent DOS on Liquidations","author":"xeku75"},{"number":866,"title":"Redemption queue blocks on the last unit of free debt","author":"cyberEth"},{"number":867,"title":"Stakers lose interest if `accrueInterest` is called constantly","author":"ck"},{"number":868,"title":"Unbounded sell() Can Reduce Vault Supply Below Minimum and Permanently Bricks buy() and consequently bricking pegging mechanism","author":"3rdeye"},{"number":870,"title":"Liquidation Can Revert if Collateral Token is Paused or Restricted","author":"futureHack"},{"number":871,"title":"PsmAsset wrongly accounted inside `accruedLocalReserves` on `accruePsmProfit`","author":"taticuvostru"},{"number":874,"title":"Zero liquidation incentive at `collateral factor threshold`","author":"dic0de"},{"number":875,"title":"Rounding Down in internalToCollateral() Can Block Liquidations for Undercollateralized Positions","author":"Umesh1145"},{"number":876,"title":"Slippage check ignores collateral received during bad debt write offs","author":"X0sauce"},{"number":877,"title":"Free Debt Inflation after Total Debt Reaches Zero","author":"Sneks"},{"number":878,"title":"Incorrect Debt Validation in setRedemptionStatus() Allows Borrowers to Bypass Redemption Lock-In Via Interest Accrual","author":"xeku75"},{"number":880,"title":"Inconsistent decimal handling for collateral deposits and withdrawals leading to under-withdrawal for funds","author":"dic0de"},{"number":881,"title":"Local reserve fee stays mutable after immutability deadline","author":"cyberEth"},{"number":882,"title":"Protocol lacks on-chain protections for depeg scenarios (price shock / PSM depeg) \u2192 cascading liquidations, PSM drain, and write-off socialization can occur without circuit breakers.","author":"Xmanuel"},{"number":883,"title":"Using rounding up when decreasing debt causes later debt to be underestimated and harms the protocol","author":"harry"},{"number":884,"title":"possible underflow  in  writeOff  Socialization.","author":"Theseersec"},{"number":885,"title":"Silent Revert during important functionality like liquidation and accruing Interest.","author":"nikhil840096"},{"number":886,"title":"Debt is unfairly distributed during writeoff","author":"0xeix"},{"number":888,"title":"It is impossible to set custom fee to zero for specific lenders.","author":"dic0de"},{"number":889,"title":"The fixed 25% of the total debt can lead to the user being liquidated for more of their position than expected","author":"coffiasd"},{"number":893,"title":"Psm buy fees inflate free debt ratio and reduce paid debt interest","author":"X0sauce"},{"number":894,"title":"Attacker will liquidate stale borrower by forcing incomplete `updateBorrower` execution","author":"0xSpider_Raphl"},{"number":898,"title":"Malicious Operator Can Prevent WriteOff to Capture Extra Interest Reserves by Manipulating Liquidatable Positions","author":"Bobai23"},{"number":900,"title":"Lack of timelock on targetFreeDebtRatio changes enables instant interest rate spikes for borrowers","author":"Sir_Shades"},{"number":901,"title":"Collateral balance and non redeemable collateral mismatch cause invariant break because of rounding issue in epoch increment","author":"copperscrewer"},{"number":905,"title":"Inconsistent halfLife Logic Can lead to Early Liquidations","author":"s4bot3ur"},{"number":906,"title":"Protocol Insolvency via Fee-on-Transfer Tokens","author":"hirusha"},{"number":908,"title":"Self-Liquidation Allowed, Bypassing External Liquidator Incentives","author":"Sneks"},{"number":911,"title":"Single StalenessThreshold for Multiple Oracle Feeds Enables Stale Data Consumption","author":"rj_eth26"},{"number":912,"title":"`buy()` and `sell()` use inconsistent asset accounting methods causing `freePsmAssets` imbalance when using ERC4626 vaults with fees","author":"cheng"},{"number":913,"title":"Collateral for redeemers is miscalculated","author":"0xeix"},{"number":914,"title":"Deposit event mis-reports shares on first deposit (ERC4626 compliance)","author":"dantehrani"},{"number":919,"title":"Attackers can cause inflation on debt by redeeming","author":"whitehair0330"},{"number":920,"title":"Front-Running of Liquidation via Small Debt Adjustment","author":"aua_oo7"},{"number":925,"title":"Attacker can game the repayment for the Lender Contract by self-liquidating their position","author":"KrisRenZo"},{"number":926,"title":"Cannot set custom fee bps to 0 for a specific lender when global fee > 0 (contrary to intuitive reading of docs)","author":"dantehrani"},{"number":928,"title":"Vault Decimal Incompatibility (Hardcoded Constants cause Deployment Failure for USDC)","author":"ZeronautX"},{"number":932,"title":"getLiquidationIncentiveBps Uses Stale Debt","author":"Theseersec"},{"number":936,"title":"Phantom Interest via WriteOff DoS (Failed WriteOff leaves Bad Debt on books)","author":"ZeronautX"},{"number":938,"title":"Rounding / lazy-redemption mismatch allows epoch indices to be queued without corresponding collateral removal, breaking collateral accounting and enabling write-off / liquidation exploitation","author":"Cara"},{"number":940,"title":"Stuck Bad Debt Zone (Economic Parameters create Unliquidatable Dead Zone)","author":"ZeronautX"},{"number":941,"title":"freePsmAssets Not Included in Total Debt During Write-Off Redistribution","author":"gkrastenov"},{"number":943,"title":"Sequential Liquidations Can Exceed the Intended 25% Liquidation Cap","author":"Sneks"},{"number":944,"title":"Bypass min debt limit by redeem and switch debt mode","author":"0xc0ffEE"},{"number":949,"title":"Hard-Coded MIN_SHARES Causes First-Depositor DoS and Unbounded Economic Loss","author":"la-arana-inteligente"},{"number":950,"title":"Incorrect Price Normalization for Non-18 Decimal Collateral","author":"Theseersec"},{"number":952,"title":"Rounding in decreaseDebt() will leave non-zero debt shares after all debt is repaid, breaking core accounting invariants","author":"Umesh1145"},{"number":953,"title":"Share Price Deflation on Every Redemption","author":"shieldrey"},{"number":954,"title":"Arbitrary Collateral Recipient Enables Theft Laundering","author":"ZeronautX"},{"number":957,"title":"PSM Vault Accounting Discrepancy in `sell()` Function Causes Protocol to Undervalue Holdings","author":"PowPowPow"},{"number":960,"title":"Incorrect internalAmount lead to over/under withdrawal of collateral","author":"ChainProof"},{"number":962,"title":"Redemption of Last Free Debt Causes Division by Zero Revert","author":"PowPowPow"},{"number":963,"title":"Vault with exchange rate greater than 1, will become incompatible.","author":"nikhil840096"},{"number":966,"title":"An attacker can erase their own debt without repayment by artificially advancing epochs and exploiting stale position reconciliation","author":"Blackdruid"},{"number":967,"title":"Rounding mismatch in freePsmAsset accounting","author":"X0sauce"},{"number":969,"title":"Timestamp Manipulation in Oracle Staleness Check","author":"ZeronautX"},{"number":974,"title":"Pending Operator State Hygiene Issue","author":"ZeronautX"},{"number":984,"title":"Epoch transition allows borrowers to avoid redemption by exploiting timing","author":"Cara"},{"number":986,"title":"`Lens` Desynchronization hides Insolvent Positions from Liquidators","author":"befree3x"},{"number":988,"title":"PSM Vault Share Conversion Discrepancy Causes Undercollateralized Stablecoin Issuance and Sell Function Revert","author":"KrisRenZo"},{"number":989,"title":"Incorrect gas-sanity checks in try/catch allow suppression of OOG failures due to EIP-150 gas reduction","author":"Cara"},{"number":990,"title":"`freePsmAssets` state variable will get underflow after some time.","author":"nikhil840096"},{"number":991,"title":"Operator Will Mint Coins Without Increasing Debt via PSM Profit Extraction","author":"Umesh1145"},{"number":993,"title":"Precision Loss on Collateral Withdrawal Causes Permanent Loss Of Funds","author":"0xMafiaBug"},{"number":994,"title":"``Vault.sol`` is not ``ERC4626`` Compliant.","author":"0xTarnished"},{"number":996,"title":"Buy function does not convert psmAsset to coin using oracle price leading to revenue losses","author":"taticuvostru"},{"number":998,"title":"Borrowers are able to borrow without providing collateral","author":"air_0x"},{"number":999,"title":"InterestModel Underflow Can Permanently Disable Interest Accrual","author":"elyas"},{"number":1003,"title":"Zero Operator Configuration Causes Permanent Lock of Local Reserve Fees","author":"Razkky"},{"number":1005,"title":"First-deposit small-amounts revert with Panic underflow instead of ZERO_SHARES (previewDeposit mismatch)","author":"dantehrani"},{"number":1007,"title":"Lack of PSM state synchronization in Lender will cause denial of service for users","author":"Venom"},{"number":1009,"title":"Slippage check missing during deposit of funds in the vault.","author":"nikhil840096"},{"number":1014,"title":"USDC/USDT depeg allows minting par Coin and draining collateral via redemption","author":"0xShoonya"},{"number":1015,"title":"PSM buy() Creates Immediate Bad Debt by Minting Coins Based on Input Amount Instead of Actual Vault Backing","author":"0xscater"},{"number":1019,"title":"PSM reserve accounting drift can permanently brick sell() via underflow despite remaining redeemable assets","author":"web3made"},{"number":1023,"title":"Borrowers Can Avoid Debt Redistribution by Entering or Exiting Immediately Before Redistribution","author":"theholymarvycodes"},{"number":1024,"title":"Dust Share Rounding During Epoch Transitions Causes Accounting Mismatch","author":"PowPowPow"},{"number":1028,"title":"A borrower will repay without interest harming vault stakers and reserves","author":"DSbeX"},{"number":1031,"title":"Vault Donation Attack Can Inflate Share Price and Grief Depositors","author":"PowPowPow"},{"number":1032,"title":"The `stalenessThreshold == 0` forces perpetual reduce-only mode, bricking adjust() borrow/withdraw flows","author":"web3made"},{"number":1035,"title":"Liquidation Incentive Increases with Successive Partial Liquidations, Leading to Excessive Liquidator Profit and Borrower Harm","author":"gneiss"},{"number":1036,"title":"Full repayment for redeemable borrowers can zero out totalFreeDebt due to type(uint).max misuse in decreaseDebt","author":"0xKann"},{"number":1037,"title":"Unreachable writeOff() Threshold Leading to Lingering Bad Debt","author":"PeterSR"},{"number":1039,"title":"receive an incorrect collateral withdrawal amount (often reverting) due to inconsistent collateralDelta unit interpretation","author":"queen"},{"number":1040,"title":"Liquidation Can Be Manipulated In-Block to Evade Redistribution","author":"theholymarvycodes"},{"number":1042,"title":"Borrowers can self-liquidate their unsafe positions to claim their collateral and distribute remaining debts to other borrowers","author":"iamephraim"},{"number":1044,"title":"Incorrect freePsmAssets tracking in sell() function with fee-charging vaults","author":"mladenov"},{"number":1045,"title":"`Lender.redeem` incorrectly checks for the non redeemable balance requirement using an amount that has the fee subtracted.","author":"ck"},{"number":1049,"title":"Missing Debt Shares Update in ```updateBorrower``` Causes Loss of User Funds and Underwater Positions","author":"0xpoison"},{"number":1050,"title":"Users can use flash loans to extract the interest from the vault","author":"0xeix"},{"number":1051,"title":"Function sell uses freePsmAssets -= assetOut rather than subtracting the actual amount delivered by the vault causing ghost profit plus shortfall","author":"AestheticBhai"},{"number":1054,"title":"Deployer can set only the PSM asset to mint unbacked coins from Lender, at the cost of users.","author":"wickie"},{"number":1060,"title":"Debt positions can fall below the configurable `minDebt` which can cause liquidations to become unprofitable","author":"deadmanwalking"},{"number":1066,"title":"A user can frontrun bad debt write-offs by changing his debt type to minimize his penalty relative to other borrowers","author":"deadmanwalking"},{"number":1068,"title":"Incorrect `Deposit` event emission in `Vault.deposit` violates ERC4626","author":"0xsai"},{"number":1069,"title":"`coinOut` is always minted based on the `assetIn` not taking into account the potential fees","author":"0xeix"},{"number":1072,"title":"Liquidation Mechanics Enable Profitable Bad Debt Exploits","author":"0xdoichantran"},{"number":1073,"title":"The liquidator can use fewer coins to liquidate the position, simultaneously increasing the bad debt incurred by the protocol.","author":"0xpiken"},{"number":1074,"title":"**Operator** Can Purchase `Coin` with `psmAsset` After the **Immutability Deadline**","author":"richardo"},{"number":1075,"title":"Immutable Staleness Threshold Causes Incorrect Price Freshness Validation When Chainlink Updates Heartbeat Parameters","author":"KrisRenZo"},{"number":1077,"title":"First-deposit frontrunning enables permanent vault griefing via MIN_SHARES inflation","author":"Blackdruid"},{"number":1080,"title":"PSM Vault Share Price Appreciation Causes Permanent Share Lock and False Free Debt Ratio Inflation","author":"KrisRenZo"},{"number":1081,"title":"PSM Vault Profit Inclusion in Free Debt Ratio Calculation Causes Inflated Interest Accrual for Paid Debt Borrowers","author":"KrisRenZo"},{"number":1082,"title":"Rounding Inconsistencies in Redemption Mechanisms Enable Cumulative Value Extraction","author":"Jumcee"},{"number":1084,"title":"Bad debt socialization conditions are too aggressive and will unfairly penalize other borrowers more than necessary","author":"deadmanwalking"},{"number":1085,"title":"Insufficient Slippage Protection in PSM Vault Deposit Causes Protocol Asset Loss","author":"KrisRenZo"},{"number":1086,"title":"PSM Buy/Sell Functions Assume 1:1 Price Parity Without Oracle Checks, Enabling Arbitrage and Create Protocol Insolvency","author":"Bobai23"},{"number":1096,"title":"writeOff` leaks collateral to arbitrary address allowing underwater borrowers to steal locked funds","author":"ReidnerM"},{"number":1097,"title":"Unsafe `uint` cast of `-wadLn` may cause interest calculation to explode","author":"hemireal4-sketch"},{"number":1099,"title":"First depositor will overpay for shares due to misleading `previewMint` function","author":"cosminm53"},{"number":1104,"title":"ERC4626 vault fees will cause PSM accounting drift and potential DoS for users","author":"joshuam33"},{"number":1106,"title":"Borrowers are undercharged collateral during redemption","author":"0xsai"},{"number":1107,"title":"Protocol will accept stale oracle prices affecting borrowers, liquidators, and redeemers","author":"SnowX"},{"number":1113,"title":"`Lender.decreaseDebt` sets `totalPaidDebt` to `0` even when `totalPaidDebtShares` is greater than `0`","author":"ck"},{"number":1115,"title":"First Depositor Can Steal All Pre-Accrued Vault Yield","author":"Hei"},{"number":1116,"title":"Invalid Check in `getFeeOf` Prevents Setting Zero Fees","author":"oxGan1"},{"number":1118,"title":"Reserves counters (uint120) can overflow and brick accrual","author":"edger"},{"number":1122,"title":"Share Calculation Bug Causes Liquidation DoS","author":"0xpoison"},{"number":1124,"title":"Custom Fee Logic Cannot Set Zero Percent Fees","author":"0xheartcode"},{"number":1133,"title":"MEV bots will front-run oracle price recovery to extract collateral from temporarily underwater borrowers","author":"PowPowPow"},{"number":1136,"title":"FreePsmAssets Understatement with Vault Withdrawal Fees","author":"yovchev_yoan"},{"number":1139,"title":"Contradictory Share Price Behavior During Write-offs Violates Stated Monotonicity Invariant Leading to Incorrect Debt Socialization","author":"KrisRenZo"},{"number":1140,"title":"PSM seller can trigger underflow and PSM exit failure due to unchecked `freePsmAssets` subtraction","author":"Diavolo"},{"number":1141,"title":"Redemption Mechanism Decreases Free Debt Share Price Breaking Share Price Monotonicity Invariant","author":"KrisRenZo"},{"number":1143,"title":"Inclusion of Non-Redeemable PSM Assets in Free Debt Ratio Calculation Causes Artificially Suppressed Interest Rates and Revenue Loss for Protocol Stakers","author":"KrisRenZo"},{"number":1145,"title":"Vault will emit incorrect Deposit events breaking ERC4626 compliance","author":"cholakovvv"},{"number":1147,"title":"Hardcoded Liquidation Parameters Prevent Documented Operator Adjustments and Eliminate Critical Protocol Risk Management Flexibility","author":"KrisRenZo"},{"number":1150,"title":"Inconsistent Immutability Implementation of `redeemFeeBps` Contradicts Protocol Documentation and Prevents Critical Fee Adjustments Post-Deadline","author":"KrisRenZo"},{"number":1151,"title":"users is allowed to change collateral to nonRedeemable even in case of unhealthy position adds new bad debt to system","author":"moray5554"},{"number":1152,"title":"PSM-backed stablecoin cannot be redeemed","author":"xiaoming90"},{"number":1153,"title":"Incorrect `maxMint` Implementation Causes Transaction Revert Due to Uncapped Return Value and MIN_SHARES Overflow","author":"KrisRenZo"},{"number":1155,"title":"Insufficient Liquidation Incentives for Small Undercollateralized Positions Leads to Accumulation of Bad Debt","author":"KrisRenZo"},{"number":1156,"title":"Missing Fee Implementation in PSM Sell Operation Causes Complete Loss of Protocol Revenue When PSM Vault is Not Configured","author":"KrisRenZo"},{"number":1158,"title":"Async epoch will zero out borrower debt and allow free collateral withdrawal","author":"AestheticBhai"},{"number":1159,"title":"Incorrect Liquidatable Debt Calculation Due to Missing Liquidation Incentive Accounting Causes Inaccurate Liquidation Assessments","author":"KrisRenZo"},{"number":1160,"title":"Fixed 25% partial liquidation degrades collateral-to-debt ratio making positions progressively unhealthier and full liquidation impossible","author":"KrisRenZo"},{"number":1161,"title":"Lack of Liquidation Protection in Position Adjustment Allows Borrowers to Frontrun Liquidations and Bypass Penalties","author":"KrisRenZo"},{"number":1165,"title":"Authorization Check Bypass Due to Early Return Allows Unauthorized Position Manipulation and Bad Debt Griefing","author":"KrisRenZo"},{"number":1166,"title":"Missing Solvency Check in Redemption Status Changes Enables Debt Inflation and Position Insolvency Through Repeated Status Toggling","author":"KrisRenZo"},{"number":1169,"title":"Rounding Down in Token Decimal Conversion Creates Permanent Asset Loss Through Dust Accumulation","author":"KrisRenZo"},{"number":1172,"title":"Excessive liquidation incentives in `getLiquidationIncentiveBps()` can worsen position health instead of improving it during liquidation","author":"KrisRenZo"},{"number":1173,"title":"Perverse Liquidation Incentive Design Causes Delayed Liquidations and Increased Bad Debt Risk","author":"KrisRenZo"},{"number":1174,"title":"Vault will revert ERC4626 view functions for integrators","author":"Umesh1145"},{"number":1176,"title":"Excessively High Write-Off Threshold (100x) Causes Irreversible Bad Debt Accumulation for the Protocol","author":"KrisRenZo"},{"number":1177,"title":"Operator can steal funds/extract values via parameter changes","author":"xiaoming90"},{"number":1178,"title":"Fixed Exchange Rate Redemption During Undercollateralization Causes Unfair Loss Distribution for Late Redeemers","author":"KrisRenZo"},{"number":1179,"title":"Incorrect Linear Interpolation Boundaries in `getLiquidationIncentiveBps` Causes Disproportionate Liquidation Incentives at Range Extremes","author":"KrisRenZo"},{"number":1180,"title":"Missing Deadline Parameter in `sell()` Function Enables Stale Transaction Execution at Unfavorable Rates","author":"KrisRenZo"},{"number":1181,"title":"Potential insolvency for selling coins","author":"0xc0ffEE"},{"number":1182,"title":"Incorrect Interest Distribution Logic Unfairly Penalizes Stakers When Total Staked Is Less Than Total Paid Debt","author":"KrisRenZo"},{"number":1183,"title":"Insufficient Epoch Threshold Allows totalFreeDebtShares to Be Scaled to Zero, Enabling Free Minting and Complete Protocol Insolvency","author":"KrisRenZo"},{"number":1192,"title":"`Vault.maxDeposit` and `Vault.maxMint` does not account for potential `totalSupply` overflow","author":"dandan"},{"number":1194,"title":"Rounding Loss in Collateral Conversions Can Permanently Break Non-Redeemable Collateral Invariant","author":"0xHexed"},{"number":1203,"title":"ERC4626 PSM integration lets early sellers drain reserves and DoS later redemptions","author":"0xnija"},{"number":1206,"title":"Liquidatable borrower can redeem and self liquidate to extract excess collateral at the expense of free debt users","author":"Shalala"},{"number":1207,"title":"Interest Dependency in totalAssets() Allows Share Minting Ratio Manipulation","author":"ChainProof"},{"number":1208,"title":"Compounding interest is lost if `Lender.accrueInterest` is not called every block","author":"dandan"},{"number":1209,"title":"Vault breaks compliance by not minting exact amount of shares on first deposit","author":"0rpse"},{"number":1213,"title":"The vault is in not in compliance with the EIP 4626","author":"ChainProof"},{"number":1215,"title":"Redeemers will lose dust amount when collateral is less than 18 decimals","author":"yaioxy"},{"number":1216,"title":"ERC4626 maxDeposit()/maxMint() Violates Standard by Not Reflecting MIN_SHARES Requirement","author":"SiddiqX7860"},{"number":1218,"title":"writeOff() can be called by an owner leads to unfair advantage","author":"moray5554"},{"number":1221,"title":"Rounding in Debt Share Accounting Creates a Dust Fixed-Point, Preventing Full Liquidation or Repayment","author":"futureHack"},{"number":1225,"title":"Partial yield from `psmVault` could be permanently locked within `Lender`","author":"0xpiken"},{"number":1226,"title":"PSM Misaccounting with Fee-Charging ERC-4626 Vaults","author":"rubencrxz"},{"number":1228,"title":"Interest minted to vault causes permanent loss of funds","author":"ke1caM"},{"number":1229,"title":"Unfair Borrower Liquidation Due to Manipulated Redemption Index","author":"Sneks"},{"number":1230,"title":"A malicious oracle will disable liquidations causing lenders to accumulate bad debt","author":"Hei"},{"number":1234,"title":"Liquidation safety invariant is broken when oracle malfunctions","author":"bbl4de"},{"number":1235,"title":"Lack Of Slippage Protection in withdraw and redeem functions","author":"yoooo"},{"number":1236,"title":"Collateral accounting invariant is effectively broken until all borrowers update their positions","author":"bbl4de"},{"number":1237,"title":"Epoch System Design Issue: Unfair Collateral Distribution and Gas Inefficiency When All Borrowers Remain in Same Epoch","author":"Wolf_Kalp"},{"number":1240,"title":"Final free-debt redemption reverts on division by zero, blocking full exit","author":"Negin"},{"number":1242,"title":"Lack of economic incentive and restrictive write-off threshold creates an \"Insolvency Gap,\" leading to permanent loss (bad debt) and denial of service (DoS) for the protocol.","author":"Venom"},{"number":1244,"title":"ERC4626 previewDeposit Inconsistency","author":"shieldrey"},{"number":1245,"title":"Bogus gas-guard turns any interest/write-off failure into a silent no-op","author":"0xShoonya"},{"number":1248,"title":"Decimal Mismatch in Withdrawal Leading to Complete Loss of User Funds","author":"DemiGods"},{"number":1249,"title":"Frontrunning redeem calls allows attacker to steal most of free debt yield","author":"copperscrewer"},{"number":1256,"title":"PSM Minting Disabled After Deadline","author":"ChaosSR"},{"number":1258,"title":"`previewDeposit()` and `previewMint()` outputs differ for the first deposit violating the spec","author":"0xeix"},{"number":1259,"title":"Flawed redemption logic incorrectly repays all the debt in certain cases without seizing enough collateral in the for loop","author":"hard1k"},{"number":1260,"title":"There may be loss of PSM assets","author":"0xc0ffEE"},{"number":1261,"title":"No differentiation between coins minted or sold from the PSM and coins borrowed through CDP positions can cause PSM users to be unable to redeem and manipulate interest rates.","author":"deadmanwalking"},{"number":1262,"title":"Psm reserves are not always sufficient to redeem psm-backed stablecoin supply","author":"slavina"},{"number":1263,"title":"`psmAsset` approval to vault cannot be increased","author":"0xapple"},{"number":1266,"title":"Asymmetric collateralDelta units break withdrawals for non 18 decimal collateral","author":"emmanuel_ewah"},{"number":1267,"title":"Critical Liquidation Health Score Deterioration: Cascading Liquidations Due to Missing Post-Liquidation Health Validation","author":"Wolf_Kalp"},{"number":1269,"title":"Incorrect liquidation set up leads to liquidation spiral","author":"ke1caM"},{"number":1272,"title":"Liquidators will cause worsening insolvency for borrowers through partial liquidations","author":"khaye26"},{"number":1277,"title":"Borrowers Can Escape Debt Without Repaying Through Epoch Transitions","author":"Umesh1145"},{"number":1280,"title":"Double round-up in redemption index + borrower application causes excess collateral seizure and broken accounting","author":"0xeix"},{"number":1281,"title":"ERC4626 `psmVault` drawdowns desync `freePsmAssets`, causing PSM `sell()` DoS and under-accrual of interest via a skewed free-debt ratio","author":"unineko"},{"number":1282,"title":"Missing Chainlink Oracle Validation","author":"Theseersec"},{"number":1286,"title":"Users will receive zero collateral on withdrawal due to collateralDelta unit misinterpretation","author":"auditorshambu"},{"number":1287,"title":"Attacker can become first depositor and make profit","author":"sakibcy"},{"number":1288,"title":"# Partial Liquidations Worsen Borrower Health and Accelerate Bad Debt Accumulation","author":"Orhukl"},{"number":1292,"title":"RedeemFee cannot be claimed","author":"ke1caM"},{"number":1293,"title":"The Vault contract is not compliant with ERC4626.","author":"ChaosSR"},{"number":1294,"title":"`decreaseDebt(type(uint).max)` uses `getDebtOf()` (rounds UP) for amount but raw storage for shares, orphaning `totalFreeDebtShares` when `totalFreeDebt` reaches zero","author":"unineko"},{"number":1295,"title":"writeOff Function Fails on Zero Collateral Transfer","author":"LonWof-Demon"},{"number":1296,"title":"ERC-4626 violation: maxDeposit() / maxMint() do not reflect revert conditions caused by accrueInterest()","author":"al0x23"},{"number":1302,"title":"Seller will lose dust and protocol cannot recover it when psmVault is set","author":"yaioxy"},{"number":1304,"title":"Interest accrual fails due to missing WAD scaling in exponential growth & decay branches","author":"shieldrey"},{"number":1305,"title":"Partial Liquidation Unconditionally Triggers Full Write-Off Allowing Minimal Repayment to Seize All Collateral","author":"Zabid27"},{"number":1307,"title":"Inconsistent first-deposit MIN_SHARES handling makes deposit() strictly worse than mint() and can cause unexpected loss of shares for first depositors","author":"0xKann"},{"number":1309,"title":"Liquidators will force borrowers into a dust-debt state that blocks future debt adjustments","author":"Le_Rems"},{"number":1311,"title":"PSM Vault Total Supply Check Blocks Initial Deposits","author":"0xnightswatch"},{"number":1312,"title":"No slippage protection on `Vault`","author":"sakibcy"},{"number":1316,"title":"Missing deadline enforcement in setLocalReserveFeeBps()","author":"shreyashkhare_70"},{"number":1319,"title":"stakers receive bigger reward unfairly because of incorrect order within accrueInterest()","author":"moray5554"},{"number":1321,"title":"`updateBorrower()` zeroes out small shares during epoch transition, allowing attacker to steal borrowed funds with zero debt","author":"blockace"},{"number":1324,"title":"Immutable Oracle Staleness Threshold Risks the protocol","author":"0xlucky"},{"number":1328,"title":"Violation of EIP4626 in function previewdeposit","author":"slowpoke"},{"number":1330,"title":"inability to fully liquidate debt leads to bad debt accruing","author":"moray5554"},{"number":1331,"title":"Coin Burning  are unrestricted","author":"khaye26"},{"number":1332,"title":"EIP-4626 Compliance Violation: Missing maxDeposit/maxRedeem Checks","author":"Marketer7"},{"number":1336,"title":"Interest calculation suffers from exponential compounding instead of linear accumulation","author":"cheng"},{"number":1338,"title":"PSM Yield Profit Is Incorrectly Included in `freePsmAssets`, Artificially Inflating Free Debt Ratio and Distorting Interest Rate Dynamics","author":"Bobai23"},{"number":1340,"title":"PSM sell() Miscalculates freePsmAssets Reduction when Vault Charges a Withdrawal Fee, Leading to Theft via False Profit Accrual.","author":"0xscater"},{"number":1341,"title":"Unnecessary reverts in the `Lender::setRedemptionStatus` function due incorrect require statement","author":"hard1k"},{"number":1342,"title":"Wrong ERC4626 conversion in the `sell()` function","author":"0xeix"},{"number":1343,"title":"Oracle Deadlock will block emergency bad debt write-offs causing permanent unbacked liabilities for the Monolith protocol","author":"Venom"},{"number":1344,"title":"Fixed Oracle Price Unwind Duration May Cause Forced Liquidations or Delayed Risk Resolution","author":"0xlucky"},{"number":1345,"title":"Non-PSM reward tokens can become stuck in lender contract when integrating reward-bearing ERC4626/URD-style PSM vaults","author":"AestheticBhai"},{"number":1347,"title":"psmVault share price drop leads to wrong freePsmAssets state leading to wrong borrow rate and interest used","author":"copperscrewer"},{"number":1351,"title":"Redemption accounting overcharges borrowers due to double round-up violating critical invariant","author":"0xShoonya"},{"number":1354,"title":"Attacker Will Drain Entire Collateral Balance Through Incorrect Decimal Conversion","author":"sourav_DEV"},{"number":1357,"title":"Vault is unusable for tokens with low decimals (USDC, WBTC) due to excessive MIN_SHARES","author":"BARAKOODAH"},{"number":1359,"title":"PSM vault redeem causes freePsmAssets to be understated and artificially lowers getFreeDebtRatio() leading to higher interest rate","author":"valicera"},{"number":1365,"title":"Arbitrageurs will drain PSM reserves from the protocol","author":"Le_Rems"},{"number":1368,"title":"Borrower will escape debt and recover collateral at the expense of other borrowers","author":"aman"},{"number":1369,"title":"ERC4626 ( PSM )rounding breaks sells and can DoS exits","author":"0xnija"},{"number":1371,"title":"Liquidation Incentive Worsens Position Health at High LTV","author":"Sir_Shades"},{"number":1374,"title":"Potential Redemption Failures Due to PSM Vault Cooldowns","author":"molaratai"},{"number":1378,"title":"Redemption Fees are not collected by the protocol; they are implicitly refunded to the Borrower","author":"hirusha"},{"number":1381,"title":"Whenever there is bad debt any borrower can just switch his redemption status so as to incur less debt.","author":"Varun_05"},{"number":1382,"title":"Operator will Drain PSM Liquidity Affected Protocol Users","author":"basia"},{"number":1385,"title":"Redeemers will unfairly seize collateral from borrowers with stale epoch data","author":"mathriel"},{"number":1389,"title":"Incorrect Supply Rate Capping Logic and condition causes Unnecessary Loss to Vault Stakers","author":"0xlucky"},{"number":1393,"title":"Users will mint unbacked Monolith Coins as PSM Buy logic ignores Vault entry fees","author":"Yuubee"},{"number":1394,"title":"Oracle Failure Will Brick Entire Protocol Through Price=1 Assignment","author":"sourav_DEV"},{"number":1397,"title":"Vault doesnt comply with ERC4626","author":"7"},{"number":1398,"title":"Interest accrues on bad debt positions between liquidation unprofitability and write-off threshold, minting unbacked stablecoin.","author":"p1ramide"},{"number":1400,"title":"Immutable Staleness Threshold Causes Persistent Reduce-Only Mode","author":"0xnightswatch"},{"number":1403,"title":"buy() function is not compatible with erc4626 vaults that implement a deposit fee, leading to lender insolvency","author":"d33p"},{"number":1405,"title":"PreviewMint adds MIN_SHARE to the shares during first deposit.","author":"joshuajee"},{"number":1407,"title":"psmVault shares if volatile cause issues when trying to redeem coins minted through psmAssets with psmAssets","author":"copperscrewer"},{"number":1408,"title":"`Lender::writeOff` can fail when collateral is zero","author":"CovenantGuard_Sec"},{"number":1409,"title":"Due to missing health factor check in the `setRedemptionStatus` function users can avoid liquidations by changing there flags which will lead to insolvent positions in the end","author":"hard1k"},{"number":1414,"title":"`writeOff()` Reverts When Collateral Balance Is Zero","author":"Nyxx"},{"number":1417,"title":"Multiple ERC-4626 Specification Violations in Vault.sol","author":"Wolf_Kalp"},{"number":1419,"title":"Attacker can deposit tokens and manipulate the protocol","author":"sakibcy"},{"number":1423,"title":"Liquidation blocked when oracle returns zero price","author":"iamgeorgi"},{"number":1428,"title":"user can frontrun and backrun redeem , so his collateral is not affected","author":"0xlucky"},{"number":1430,"title":"Insolvency risk by liquid to iliquid token without updating factor","author":"Le_Rems"},{"number":1431,"title":"Share Price decreases due to\u00a0rounding direction mismatch and redemption lazy\u00a0updates","author":"touristS"},{"number":1432,"title":"Attacker Will Mint Unlimited Stablecoins Through PSM Value/Amount Mismatch","author":"sourav_DEV"},{"number":1433,"title":"Epoch Progression Failure Causes Unfair Collateral Seizures for New Borrowers","author":"rj_eth26"},{"number":1434,"title":"Borrowers will bypass maxBorrowDelta protection by exploiting interest accrual to manipulate the debt-to-shares ratio and borrow more than intended limits","author":"mathriel"},{"number":1435,"title":"Missing Initialization of `feeBps`","author":"Mrmatrixxx"},{"number":1436,"title":"Vault breaks with Fee-on-Transfer tokens leading to fund loss","author":"BARAKOODAH"},{"number":1438,"title":"Redemption fee is not credited to anyone","author":"0xeix"},{"number":1439,"title":"Interest accrual mints unbacked stablecoins without global collateralization check","author":"cheng"},{"number":1444,"title":"Nonce Manipulation Address Prediction Attack","author":"SnowX"},{"number":1449,"title":"Borrowers are unable to partially repay in case oracle price goes wrong","author":"0xc0ffEE"},{"number":1451,"title":"Liquidation Fees Not Included in Solvency Check: Positions Pass Solvency Checks But Fail During Liquidation","author":"Wolf_Kalp"},{"number":1452,"title":"Event being emitted before shares deduction breakes the invariant","author":"p1ramide"},{"number":1453,"title":"Fixed Gas Requirements in Try-Catch Blocks Enable Denial of Service","author":"Jumcee"},{"number":1454,"title":"Incorrect redemption index delta calculation causes borrower collateral misaccounting","author":"0xeix"},{"number":1455,"title":"absence of check when 0 shares are burnt could lead to disadvantage to other borrowers","author":"0xlucky"},{"number":1456,"title":"External Interest Calculation Can Cause Deposit/Redeem Reverts","author":"molaratai"},{"number":1458,"title":"Epoch mechanism updates only once even if current tFDS/tFD is > 1e18","author":"ScarletFir"},{"number":1459,"title":"Solvency Check Excludes Liquidation Incentives, Creating Liquidation Failure Risk","author":"rj_eth26"},{"number":1461,"title":"Discrepancy mint vs deposit first depositor (lost of value on the wrong path)","author":"Le_Rems"},{"number":1462,"title":"Front-Running Liquidation Vulnerability: Users Can Block Legitimate Liquidations Through Mempool Manipulation","author":"Wolf_Kalp"},{"number":1463,"title":"Protocol Will Become Insolvent Through Unlimited Bad Debt Socialization","author":"sourav_DEV"},{"number":1466,"title":"Vault.totalAssets() Includes Unrealized Assets, Violating ERC-4626","author":"BroRUok"},{"number":1467,"title":"Oracle Will Steal User Funds Through Reentrancy During Price Fetching","author":"sourav_DEV"},{"number":1469,"title":"Precision Mismatch Between Accounting and Transfer in redeem() Causes Collateral Over\u2011Accounting","author":"0xvictorsr"},{"number":1470,"title":"Users Will Be Unable to Borrow During Oracle Failure Due to Zero Borrowing Power","author":"sourav_DEV"},{"number":1471,"title":"A user can be liquidated by manuplating the totalFreeDebt value","author":"ByteFable"},{"number":1474,"title":"Unburned Bad Debt in writeOff() Causes System Insolvency Risk","author":"0xvictorsr"},{"number":1475,"title":"ERC-4626 Compliance: previewDeposit Mismatch causes Revert (EIP Violation)","author":"OxNoble"},{"number":1476,"title":"A liquidator can gain an unfair advantage by liquidating a borrower immediately after redemptions have reduced their collateral.","author":"0xvictorsr"},{"number":1478,"title":"PSM Asset Depeg Allows Arbitrage and Protocol Insolvency","author":"0xSomeHuntoor"},{"number":1480,"title":"Missing Borrower Health Validation in Liquidation Allows Unfair or Failed Liquidations","author":"rj_eth26"},{"number":1484,"title":"Borrower will be permanently unable to change redemption status, causing forced financial loss","author":"sourav_DEV"},{"number":1485,"title":"ERC4626 PSM vault share price / fees are ignored in buy/sell conversions, enabling undercollateralized Coin minting","author":"JohnWeb3"},{"number":1486,"title":"Vault first-deposit `MIN_SHARES` handling allows 0-share deposits that burn user assets","author":"JohnWeb3"},{"number":1489,"title":"`Lender.decreaseDebt()` can reduce global debt without burning borrower shares when `mulDivDown` rounds to zero","author":"JohnWeb3"},{"number":1490,"title":"Direct Coin donations to `Vault` can manipulate `Lender.accrueInterest()` interest split and siphon `accruedLocalReserves`","author":"JohnWeb3"},{"number":1491,"title":"`Lender.setRedemptionStatus()` can be DoS\u2019d by `maxBorrowDeltaBps` during internal debt migration","author":"JohnWeb3"},{"number":1492,"title":"`uint120` truncation in `Lender.accrueInterest()` can under-credit `accruedLocalReserves` while `totalPaidDebt` increases","author":"JohnWeb3"},{"number":1493,"title":"Missing Chainlink `latestRoundData()` sanity checks can accept stale/incomplete rounds as valid prices","author":"JohnWeb3"},{"number":1494,"title":"Assuming psmAsset is $1 stablecoin causes mispricing and unbacked Coin minting","author":"0xeix"},{"number":1496,"title":"Malicious ERC4626 PSM vault can spoof `previewRedeem()` to mint unbacked Coin via `accruePsmProfit()`","author":"JohnWeb3"},{"number":1498,"title":"Rounding down in `getLiquidationIncentiveBps()` can underestimate LTV and return 0% incentive for  liquidatable positions","author":"0xeix"},{"number":1500,"title":"Redemption toggle lets sub-min debt migrate into paid bucket without `minDebt` check","author":"x15"},{"number":1501,"title":"Free-debt share rounding lets per-account debt exceed total debt.","author":"x15"},{"number":1504,"title":"Reentrancy Attack","author":"fahyvor"},{"number":1507,"title":"PSM Buy Fee Incorrectly Drops to Zero After Immutability Deadline Causing Revenue Loss and Timing Attacks","author":"OxNoble"},{"number":1508,"title":"`Lender::accrueInterest` and `Lender::getPendingInterest` is using old `cachedGlobalFeeBps`","author":"sakibcy"},{"number":1199,"title":"`Deposit` event is wrong on the first deposit leading to non-compliance with EIP4626","author":"xiaoming90"},{"number":657,"title":"Buyers will pay lower-than-intended PSM buy fees during the fee-ramp period, reducing protocol fee revenue","author":"0xapple"},{"number":125,"title":"`Vault.deposit` Inconsistency Causes First Depositor to Lose Funds (Zero Shares Received)","author":"Wojack"},{"number":456,"title":"Missing min/max answer checks when validating Chainlink prices","author":"0xeix"},{"number":1149,"title":"`collateralDelta` is denominated differently during deposit and withdrawal","author":"xiaoming90"},{"number":1175,"title":"Collateral factor (LTV) cannot be updated","author":"xiaoming90"},{"number":731,"title":"Factory fee change is applied one interest accrual late in `accrueInterest()`","author":"deadmanwalking"},{"number":1335,"title":"Full-liquidations are not always unavailable, breaking liquidation invariant","author":"bbl4de"},{"number":1033,"title":"Users can game redemptions by quickly changing the status","author":"0xeix"},{"number":1502,"title":"Interest Accrual Silently Fails on Overflow, Causing Permanent Loss of Interest","author":"0xhsn"},{"number":805,"title":"Missing `accruePsmProfits()` in `sell()` will lead to the lost profit for the protocol between two accruals","author":"0xeix"},{"number":1219,"title":"Early sellers can drain all `psmVault` shares after a vault loss, leaving remaining PSM-minted Coin effectively unbacked and later/slower users cannot exit","author":"xiaoming90"},{"number":475,"title":"PSM Breaks Permanently due to beforeDeadline modifier in buy() , Causing Complete Collapse of Peg-Stabilization Mechanism after deadline","author":"3rdeye"},{"number":1204,"title":"A stale oracle can cause the entire user position to be liquidated","author":"xiaoming90"},{"number":278,"title":"`reapprovePsmVault()` Fails for Tokens with Approve Race Condition Protection","author":"nodesemesta"},{"number":872,"title":"`MIN_LIQIUDATION_DEBT` value can be bypassed","author":"0xeix"},{"number":1315,"title":"Redemption can revert because of the division by zero preventing full redemption","author":"0xeix"},{"number":860,"title":"Anybody can call `writeOff()` before the liquidations occur triggering socialization before liquidations","author":"0xeix"},{"number":452,"title":"Half life parameter can be set to the value that's < 24 hours while the constructor disallows that","author":"0xeix"},{"number":1268,"title":"Users will be unable to deploy Lender markets for EIP-20 compliant tokens without decimals()","author":"Marketer7"},{"number":216,"title":"Front\u2011running writeOffs can be used to shift bad debt onto slower borrowers","author":"heavyw8t"},{"number":666,"title":"acceptOperator() will cause state inconsistency for the protocol as it will not reset pendingOperator to zero","author":"Umesh1145"},{"number":1048,"title":"Missing Access Control on `Lender.sol::writeOff()` Allows Any Address to Trigger Debt Redistribution","author":"0xMafiaBug"},{"number":588,"title":"Operator can be changed after `immutabilityDeadline`","author":"tedox"},{"number":441,"title":"Incorrect maxBorrowDeltaBps Cap causes Borrowing reverts and Restricts Opertor configuration Before Immutability deadline.","author":"bughunter442"},{"number":1300,"title":"Borrower redemption accounting breaks after 5+ epochs due to capped epoch processing","author":"0xeix"},{"number":547,"title":"\"PSM `buy()` function permanently reverts for new/empty Vaults due to premature total supply check\"","author":"tonnero234"},{"number":393,"title":"MAX_DECIMALS value is deviated from the intended one specified in README","author":"0xeix"},{"number":1171,"title":"Debt share prices can decrease due to `decreaseDebt()` math","author":"xiaoming90"},{"number":19,"title":"Interest Accrual permanently fails due to overflow after inactivity","author":"Wojack"},{"number":1220,"title":"`totalAssets()` / `convertTo*` can revert","author":"xiaoming90"},{"number":1379,"title":"Borrowers can self-liquidate or self-writeOff their positions, avoiding losses and socializing debt","author":"touristS"},{"number":185,"title":"Reentrancy in liquidate allows draining collateral via ERC777 tokens due to violation of Checks-Effects-Interactions","author":"abdul171"},{"number":616,"title":"Liquidations become unprofitable at `LTV > 400%` preventing cleanup until `LTV >10000%`","author":"blockace"},{"number":1422,"title":"Interest Siphoning via Zero-Supply Vault Seeding","author":"0xShoonya"},{"number":1301,"title":"`Lender.sell` subtracts a higher value of `assetOut` than is actually redeemed.","author":"ck"},{"number":1441,"title":"collateral can be stolen when psmAsset == collateral","author":"0rpse"},{"number":826,"title":"The collateral reward is capped during liquidations creating losses for liquidators","author":"0xeix"},{"number":1499,"title":"Missing coin/USD valuation in `adjust()` doesn't account for depegs","author":"0xeix"},{"number":1210,"title":"Half-life bounds are imprecisely checked in the setter function","author":"Negin"},{"number":1076,"title":"Interest Distribution to Vault with Only MIN_SHARES Causes Permanent Loss of Accrued Interest","author":"KrisRenZo"},{"number":641,"title":"Users can deposit depegged `psmAsset` and get 1$ of coin breaking the invariants","author":"0xeix"},{"number":3,"title":"Stale Oracle linear decay mechanism allows liquidators to steal collateral from solvent borrowers by forcing liquidations at artificially low prices","author":"jacal"},{"number":4,"title":"External callers can wipe arbitrary borrowers' debt and steal their full collateral via writeOff()","author":"0_Bash"},{"number":6,"title":"Liquidations Are Allowed With A Stale Price","author":"0xSomeHuntoor"},{"number":9,"title":"Sandwich Attack on redeem(): Lack of cooldown allows borrowers to front-run redemptions and evade penalty","author":"abdul171"},{"number":10,"title":"PSM Vault Insolvency Causes Lock Funds (DoS) for Coin Holders","author":"bratwork"},{"number":11,"title":"Missing PSM Profit Accrual in accrueInterest() Causes Stale Free Debt Ratio and Incorrect Interest Rate Calculations","author":"Sai501"},{"number":12,"title":"README max token decimals doesn't match hardcoded value in the codebase","author":"heavyw8t"},{"number":13,"title":"Stale oracle handling in getCollateralPrice() lets attacker redeem and liquidate with an almost-zero price and drain collateral","author":"pecata17107"},{"number":15,"title":"Share Price Monotonicity Violation due to Rounding in Debt Repayment","author":"Merlinsan"},{"number":18,"title":"Critical: Stale Oracle Price Unwind Mechanism Enables Zero-Cost Theft via WriteOff and Liquidation","author":"Wojack"},{"number":26,"title":"writeOff can be called by anyone to steal collateral from underwater positions","author":"0xsupremedev"},{"number":27,"title":"Unhandled PSM vault losses in `accruePsmProfit()` leads to permanently inflated `freePsmAssets` and accounting corruption","author":"makeWeb3safe"},{"number":35,"title":"Reentrancy in `liquidate()` allows Collateral Double-Spending","author":"4vian"},{"number":36,"title":"Oracle Staleness  Enables Complete Theft of Borrower Collateral Through Wrongful Liquidations at Invalid Prices","author":"Pelz"},{"number":37,"title":"Stale oracle prices can be used to unfairly liquidate positions","author":"heavyw8t"},{"number":38,"title":"Any external caller can steal 100% of all borrower collateral by directly invoking writeOff()","author":"0_Bash"},{"number":40,"title":"PSM vault integration can lead to permanent loss of user funds due to unchecked redemption slippage","author":"0xsupremedev"},{"number":45,"title":"External callers can wipe arbitrary borrowers' debt and steal their full collateral via writeOff()","author":"0_Bash"},{"number":46,"title":"updateBorrower loop limitation allows borrowers to avoid collateral redemptions","author":"0xsupremedev"},{"number":49,"title":"Anyone can call writeOff() to zero a borrower\u2019s debt, socialize it to others, and steal all remaining collateral","author":"pecata17107"},{"number":51,"title":"Stale oracle keeps liquidations enabled \u2192 near-zero price seizures","author":"bratwork"},{"number":59,"title":"Attacker will drain redeemable collateral from free debt borrowers due to broken staleness handling","author":"JeRRy0422"},{"number":63,"title":"Asymmetric Decimal Handling in `adjust()`","author":"4vian"},{"number":68,"title":"Liquidations must be paused when the price is set to 0 in `getCollateralPrice()`","author":"Valves"},{"number":69,"title":"Critical logic error in\u00a0`adjust`\u00a0treats withdrawal inputs as internal 18-decimal values, causing trapped funds","author":"jacal"},{"number":73,"title":"Epoch Skipping in `updateBorrower` Causes Debt Calculation Errors and Potential Insolvency","author":"bratwork"},{"number":75,"title":"Attacker will drain most redeemable collateral from free-debt borrowers when oracle becomes stale","author":"YF"},{"number":79,"title":"Stale-oracle attacker will drain collateral from borrowers and protocol reserves","author":"mrdafidi"},{"number":80,"title":"`redeem` Function Reverts if `totalFreeDebt` is Zero, Blocking Redemptions","author":"bratwork"},{"number":81,"title":"Stale Oracle Allows Liquidator to Steal >99% of Borrower Collateral","author":"attacker_code"},{"number":82,"title":"getCollateralPrice incorrectly devalues collateral during Oracle staleness, leading to the liquidation of solvent users","author":"abdul171"},{"number":83,"title":"Liquidators abusing stale Chainlink prices will steal underpriced collateral from healthy Monolith borrowers","author":"manvita836"},{"number":84,"title":"PSM Buy functionality is permanently disabled after immutability deadline","author":"Merlinsan"},{"number":87,"title":"reapprovePsmVault() function in Lender.sol will always fail for USDT Tokens Causing Permanent DoS","author":"b_void"},{"number":88,"title":"Stale Oracle Allows Liquidations Due to Missing Liquidation Disable Flag","author":"Gakarot"},{"number":92,"title":"Division by Zero in Redeem Function Causes Complete Protocol Denial of Service","author":"Minion"},{"number":95,"title":"In the Lender.sol contract stale oracle unwind interpolation can enable liquidation during unwind window","author":"AlexScherbatyuk"},{"number":99,"title":"H-02: PSM `buy` function permanently disabled after immutability deadline, breaking peg stability","author":"Albert_Mei"},{"number":102,"title":"Lender.getCollateralPrice() staleness-branch price=1 fallback permits liquidations and redemptions at artificial unit price draining protocol collateral","author":"boodieboodieboo"},{"number":104,"title":"Lender.sell() decrements freePsmAssets by calculated assetOut instead of actualAssetOutToSeller enabling early PSM DoS and interest-rate controller miscalibration","author":"boodieboodieboo"},{"number":105,"title":"Lender.accruePsmProfit() one-sided sync ignores vault losses inflating freePsmAssets and miscalibrating interest rate controller","author":"boodieboodieboo"},{"number":109,"title":"`totalAssets()` in Vault breaks the ERC4626 specs","author":"bbl4de"},{"number":112,"title":"Oracle Staleness logic incorrectly decays price to zero without pausing liquidations, leading to collateral theft and bad debt","author":"cosin3"},{"number":114,"title":"Attackers will seize all borrower collateral","author":"fullstop"},{"number":115,"title":"`Lender.accruePsmProfit` Ignores Vault Losses, Leading to Inflated Accounting and Failed Economic Defense Mechanisms","author":"Wojack"},{"number":116,"title":"Front-Running Redemptions via Free Status Switching","author":"0xSomeHuntoor"},{"number":117,"title":"Oracle Staleness Masking Enables Catastrophic Liquidations and Redemptions at Invalid Price","author":"watsonclyde"},{"number":121,"title":"updateBorrower caps processing to 5 epochs but then resets borrowerEpoch to current epoch, permanently skipping pending redemptions","author":"zubyoz"},{"number":122,"title":"First depositor can lose 100% of funds in Vault due to incorrect MIN_SHARES handling","author":"I1iveF0rTh1Sh1t"},{"number":123,"title":"Liquidate function doesn't inforce minDebt invariant","author":"Synthrax"},{"number":124,"title":"PSM accounting bug lets `operator` mint unbacked `Coin` by exploiting fake profit","author":"grigorovv17"},{"number":126,"title":"Oracle \"Fire Sale\": Stale Prices Trigger Artificial Insolvency and Total Loss","author":"destiny_rs"},{"number":127,"title":"First-deposit MIN_SHARES can pull assets but mint 0 shares","author":"edger"},{"number":128,"title":"Oracle staleness unwind allows redeeming Coin for nearly-free collateral (full pool drain)","author":"I1iveF0rTh1Sh1t"},{"number":130,"title":"Borrowers will evade redemptions and shift loss to honest users","author":"fullstop"},{"number":131,"title":"`Lender.buy` Is Permanently Disabled After Immutability Deadline Due to Incorrect Modifier Usage","author":"Wojack"},{"number":135,"title":"Borrower can avoid debt fees","author":"Synthrax"},{"number":139,"title":"`setRedemptionStatus` allows Front-Running to evade forced position exit, breaking the Free Debt Risk/Reward invariant","author":"ReidnerM"},{"number":140,"title":"Unfair liquidations during oracle staleness due to artificially reduced asset price while liquidations are still allowed.","author":"TAdev0"},{"number":141,"title":"`Staleness Decay` mechanism unfairly liquidates solvent users during temporary Oracle latency","author":"ReidnerM"},{"number":142,"title":"Redemption Evasion via Incomplete Lazy Sync Leading to Collateral Theft in Lender.sol","author":"b_void"},{"number":143,"title":"Attacker will drain all protocol collateral as liquidations and writeOffs proceed at 1 wei price when Chainlink oracle becomes stale","author":"Yuubee"},{"number":144,"title":"Attacker can use self `writeOff` to clear debt and claim collateral during depeg or trough price manipulation.","author":"heavyw8t"},{"number":145,"title":"Attacker can unfairly buy or sell when depegs occur","author":"heavyw8t"},{"number":146,"title":"Users can lose all their funds when a PSM ERC4626 vault suffers a loss","author":"Falendar"},{"number":148,"title":"PSM `buy()` Permanently Disabled After Immutability Reached Breaks Peg Support on the Asset \u2192 Coin Side","author":"JuggerNaut"},{"number":149,"title":"Division by Zero on `Lender.redeem` When All Free Debt is Redeemed","author":"JuggerNaut"},{"number":159,"title":"Liquidator will seize full borrower collateral for minimal debt repayment","author":"Gambiteer90"},{"number":164,"title":"Stale Oracle Price Enables Total Collateral Theft via Liquidation","author":"BunnyHunter"},{"number":165,"title":"Accounting Error in sell(): freePsmAssets Decremented by Expected Amount Instead of Actual Amount Withdrawn","author":"Sai501"},{"number":168,"title":"Free Debt Borrowers are Able to Evade Collateral Redemption","author":"0xsh"},{"number":169,"title":"Stale freePsmAssets Tracking Causes Denial of Service for Users Selling Coins When PSM Vault Earns Yield","author":"0xTomioka"},{"number":170,"title":"Stale oracle path sets `price floor to 1` while leaving liquidations/redemptions enabled","author":"R.Kundan"},{"number":173,"title":"Fee changes are not applied immediately","author":"VLAAAAAADDDD"},{"number":175,"title":"Borrower will lose previous epoch's state if being inactive for over 5 epochs","author":"y4y"},{"number":179,"title":"Stale oracle price allows liquidators to fully seize borrower collateral and liquidate healthy positions almost cost-free","author":"grigorovv17"},{"number":181,"title":"Division-by-zero `sentinel` in redeem causes brittle reverts after state changes","author":"R.Kundan"},{"number":184,"title":"Stale Oracle Lets Attackers Liquidate/Write-Off at Near-Zero Price","author":"sahuang"},{"number":187,"title":"Stale cachedGlobalFeeBps Used During Interest Accrual Causes Incorrect Fee Distribution","author":"Sai501"},{"number":188,"title":"Oracle Staleness Fallback Enables Abusive writeOff/liquidate","author":"Edoscoba"},{"number":191,"title":"`accruePsmProfit` fails to sync state on external vault losses, causing corrupted Interest Rate calculations","author":"ReidnerM"},{"number":192,"title":"Zero-price fallback with `allowLiquidations == true` enables catastrophic liquidations and redemptions","author":"jo13"},{"number":194,"title":"Oracle Staleness Logic Allows Collateral Theft via Price=1","author":"Bin-Darweesh"},{"number":195,"title":"Liquidations and redemptions allowed on stale oracle via artificial price floor (`price=1` sentinel)","author":"zubyoz"},{"number":197,"title":"Lack of PSM loss handling will cause insolvency for stablecoin holders","author":"fullstop"},{"number":199,"title":"H-04: `collateralFactor` is immutable, preventing critical risk adjustments and exposing the protocol to bad debt","author":"Albert_Mei"},{"number":202,"title":"Epoch Manipulation Allows Borrowers to Skip Redemptions","author":"Bin-Darweesh"},{"number":205,"title":"PSM sell() Accounting Mismatch with Actual Vault Redemption","author":"Bin-Darweesh"},{"number":207,"title":"Redemption Front-Running via Debt Type Switching","author":"Bin-Darweesh"},{"number":208,"title":"Epoch Skipping Leads to Protocol Insolvency","author":"Bin-Darweesh"},{"number":210,"title":"Full Redemption DoS via Division by Zero","author":"Bin-Darweesh"},{"number":211,"title":"Borrowers can sandwich redemptions by toggling isRedeemable and avoid collateral reduction","author":"algiz"},{"number":212,"title":"Missing Chainlink round-completeness checks allow stale/incomplete price usage for liquidations","author":"zubyoz"},{"number":213,"title":"Attacker will steal all collateral from borrowers via write-off borrowers","author":"zcai"},{"number":214,"title":"Vault::totalAssets() may revert, violating EIP 4626","author":"shiazinho"},{"number":215,"title":"getCollateralPrice fails to disable liquidations during extended oracle staleness, allowing collateral to be drained at 1 wei price","author":"teoslaf1"},{"number":221,"title":"Stale oracle lets anyone liquidate all borrowers at ~0 price","author":"gwumex"},{"number":222,"title":"Stale oracle sets price to 1 but keeps liquidations/redemptions on, letting anyone drain collateral","author":"gwumex"},{"number":225,"title":"WriteOff Collateral Theft via Arbitrary Recipient","author":"Bin-Darweesh"},{"number":226,"title":"`freePsmAssets` variable is not updated in the event of a loss in the PSM vault, leading to incorrect borrow rate computation and loss of yield for stakers.","author":"TAdev0"},{"number":227,"title":"Edge condition will cause liquidation DoS via underflow protocol","author":"zcai"},{"number":228,"title":"Final free\u2011debt redemption always reverts (division by zero), making peg restoration impossible","author":"gwumex"},{"number":229,"title":"Stale oracle sets price to 1 but keeps liquidations/redemptions enabled, allowing collateral drain","author":"gwumex"},{"number":230,"title":"Liquidate is reentrancy\u2011unsafe \u2014 ERC777 collateral lets liquidator double\u2011dip and desyncs collateral accounting","author":"gwumex"},{"number":231,"title":"Missing reduceOnly Check in redeem() Allows Redemptions at Reduced Prices When Oracle is Stale","author":"Sai501"},{"number":234,"title":"Extreme Oracle Staleness Fails to Disable Liquidations, Enabling Complete Collateral Drainage","author":"Razkky"},{"number":239,"title":"H-05: Asymmetric unit handling in `Lender.adjust` will prevent users from withdrawing non-18-decimal collateral","author":"Albert_Mei"},{"number":245,"title":"Liquidator will steal all collateral from borrowers during oracle staleness","author":"legalwarden50"},{"number":252,"title":"Oracle Price Decay mechanism allows users to drain collateral via redeem() during stale price conditions","author":"M1troV"},{"number":255,"title":"Redemption Epoch Skipping Allows Collateral Theft","author":"kkkkkk"},{"number":257,"title":"Attacker can drain redeemable collateral from all stakers on `redeem`","author":"HeckerTrieuTien"},{"number":258,"title":"Liquidator can steal collateral via reentrancy in `liquidate()`","author":"R.Kundan"},{"number":264,"title":"JIT Mode-Switch Allows Sophisticated Borrowers to Avoid Redemption Losses","author":"jayjoshix"},{"number":265,"title":"Liquidators can drain borrower collateral on getCollateralPrice","author":"HeckerTrieuTien"},{"number":270,"title":"Unit Mismatch in lender.adjust()","author":"Smacaud"},{"number":272,"title":"Interest accrual permanently fails when calculateInterest reverts, allowing borrowers to avoid interest payments","author":"Ba17"},{"number":277,"title":"Overly stale feed price allows fully liquidating and writing off any position","author":"algiz"},{"number":282,"title":"Oracle Staleness Decays Price but Fails to Pause Liquidations leading to Mass Unfair Liquidations","author":"hodlturk"},{"number":283,"title":"Missing Access Control on writeOff() Enables Front-Run Theft of Collateral","author":"hy"},{"number":284,"title":"`getBuyAmountOut` assumes fixed 1:1 peg allowing collateral drainage during PSM asset depeg events","author":"ReidnerM"},{"number":285,"title":"Front-running the writeOff transaction to repay their loans leads to unfair debt distribution","author":"fullstop"},{"number":286,"title":"Malicious Borrowers Will Evade Liquidation Penalties and Abuse Dust Liquidations","author":"basia"},{"number":287,"title":"Critical State Desynchronization: Loop Limit in 'updateBorrower' Causes Silent Debt Erasure (Ghost Collateral) Leading to Protocol Insolvency","author":"hodlturk"},{"number":289,"title":"Attacker will steal all protocol collateral during oracle staleness by exploiting writeOff mechanism","author":"TOSHI"},{"number":291,"title":"Outdated Oracle Price Falls Back to 1, Allowing Liquidator to Seize All Collateral at Minimal Cost","author":"hy"},{"number":292,"title":"Inconsistency in `collateralDelta` unit in `adjust` function might lead to loss of funds for users.","author":"TAdev0"},{"number":299,"title":"Unsocialized PSM vault losses break PSM reserve invariant and strand late stablecoin sellers","author":"algiz"},{"number":303,"title":"PSM yield extraction before fee accrual allows front-running operator profits","author":"SnowX"},{"number":306,"title":"Operator lacks the ability to adjust `collateralFactor`","author":"tedox"},{"number":308,"title":"Unit Mismatch in adjust Function Leads to Fund Loss for Non-18 Decimal Tokens","author":"fullstop"},{"number":309,"title":"Attacker will drain PSM reserves via redemptions PSM","author":"zcai"},{"number":310,"title":"Stale-oracle price coercion with allowLiquidations enables redemption and liquidation collateral drain","author":"itsgreg"},{"number":313,"title":"Stale oracle falls back to price = 1, enabling extreme underpriced redemptions and liquidations","author":"OVERR1DE"},{"number":319,"title":"Oracle staleness coerces price to 1 and no min repay enables full collateral theft via liquidation","author":"itsgreg"},{"number":324,"title":"Fail-open stale oracle normalization enables arbitrary writeOff theft of borrower collateral","author":"itsgreg"},{"number":334,"title":"PSM accounting will ignore losses leading to incorrect free-debt ratio calculations","author":"zcai"},{"number":335,"title":"Transfer-before-commit reentrancy in Lender.liquidate enables collateral theft and ledger desync","author":"itsgreg"},{"number":338,"title":"Attacker will steal a user's entire collateral by triggering `writeOff`","author":"cosminm53"},{"number":345,"title":"Liquidators will seize solvent borrowers\u2019 collateral using stale $1 oracle floor","author":"th3hybrid"},{"number":350,"title":"Oracle Staleness Enables Mass Liquidation of Safe Positions","author":"ibrahimatix0x01"},{"number":351,"title":"Liquidator will drain borrower collateral via stale oracle floor","author":"neeloy"},{"number":353,"title":"ERC-4626 Specification Violation + DoS Vector in totalAssets()","author":"x0lohaclohell"},{"number":357,"title":"Liquidation reentrancy corrupts collateral accounting","author":"th3hybrid"},{"number":360,"title":"`Lender.reapprovePsmVault` Reverts with USDT Due to Unsafe Approval Implementation (DoS of Maintenance Function)","author":"Wojack"},{"number":361,"title":"DIVISION BY ZERO IN INTEREST CALCULATION CAUSING PERMANENT INTEREST ACCRUAL FAILURE","author":"GypsyKing18"},{"number":365,"title":"Stale Price Fallback to 1 Enables Invalid Operations","author":"0x97"},{"number":371,"title":"Final Redeemer will be Unable to Redeem Due to Division-by-Zero Revert","author":"m3dython"},{"number":372,"title":"Front-Running Debt Status Switch Enables Redemption Evasion","author":"m4ze"},{"number":377,"title":"PSM Vault Redemption Fees Will Cause Accounting Inconsistency in freePsmAssets State Variable","author":"m3dython"},{"number":379,"title":"Borrower will retain excess collateral due to incomplete redemption accounting in updateBorrower()","author":"m3dython"},{"number":384,"title":"Liquidations During Stale Price Results Loss To Users","author":"s4bot3ur"},{"number":386,"title":"Stale Oracle Prices Allow Critical Protocol Draining via Malicious Redemptions","author":"TianZun"},{"number":387,"title":"State Overwrite via Reentrancy in liquidate leads to Protocol Insolvency","author":"fullstop"},{"number":388,"title":"Sell Function Uses Calculated Amount Instead of Actual Redeemed Amount, Causing Accounting Mismatch","author":"brunacunha"},{"number":391,"title":"Stale Oracle Allows Redeemers to Drain All Redeemable Collateral","author":"bratwork"},{"number":396,"title":"PSM Loss Recording Failure","author":"richi"},{"number":397,"title":"Operator/manager can be changed even after immutability deadline","author":"0xeix"},{"number":408,"title":"`Lender.buy()` permanently locked after immutability deadline","author":"cyberEth"},{"number":409,"title":"`Vault::mint` is not compliant with EIP-4626 MUST condition","author":"farismaulana"},{"number":417,"title":"Stale oracle keeps liquidations, write-offs and redemptions live","author":"cyberEth"},{"number":419,"title":"Long-idle accrual overflows to zero, erasing interest","author":"th3hybrid"},{"number":420,"title":"getCollateralPrice() allows liquidation when the price is stale","author":"leopoldflint"},{"number":422,"title":"Small positions can be created below liquidation threshold allowing bad debt accumulation","author":"anchabadze"},{"number":424,"title":"Stale Oracle Forces Price to 1, Allowing Liquidators to Seize All Collateral at Unfair Prices","author":"jayjoshix"},{"number":434,"title":"User can create position with debt lower than min debt","author":"0xc0ffEE"},{"number":435,"title":"Stale `freePsmAssets` leads to understated free debt ratio which overcharges interests","author":"X0sauce"},{"number":437,"title":"Attacker will avoid all redemption losses by frontrunning status changes, forcing victims to absorb 100% of collateral reductions","author":"TOSHI"},{"number":445,"title":"PSM losses are never written down, leaving Coin unbacked and redemptions impossible","author":"th3hybrid"},{"number":446,"title":"PSM buy mints Coin at par against depegged/insolvent assets","author":"th3hybrid"},{"number":448,"title":"PSM buy() function permanently disabled after immutability deadline breaks peg ceiling mechanism","author":"jayjoshix"},{"number":449,"title":"Collateral price can be set to 1 without any grace period","author":"Synthrax"},{"number":450,"title":"Oracle Staleness Enables Near\u2011Zero\u2011Price Liquidations","author":"Kodyvim"},{"number":453,"title":"Inconsistent Unit System Between Deposits and Withdrawals in adjust() Function","author":"maxim371"},{"number":459,"title":"Oracle staleness decays price to near-zero while liquidations and redemptions remain enabled","author":"al0x23"},{"number":460,"title":"PSM Vault Losses Not Tracked, Causing Permanent PSM Failure","author":"maxim371"},{"number":462,"title":"Attacker Will Steal Collateral From Borrowers Without Repayment, Honest Users Absorb Bad Debt","author":"mathriel"},{"number":463,"title":"Missing conversion to internal representation in adjust()","author":"leopoldflint"},{"number":465,"title":"Vault emits ERC-4626 Deposit event with incorrect shares value on first deposit","author":"v_2110"},{"number":469,"title":"An attacker will steal all borrower collateral and bankrupt the protocol when the oracle becomes stale","author":"0xHexed"},{"number":470,"title":"Stale Oracle Prices allow attackers to steal all Protocol Collateral via writeOff()","author":"tonnero234"},{"number":471,"title":"Borrowers can prevent impacts from socialized bad debt","author":"0xc0ffEE"},{"number":484,"title":"PSM buy() Disabled After Deadline While sell() Remains Active, Causing Irreversible Reserve Drain","author":"xeku75"},{"number":488,"title":"Redemption Avoidance via Status Switching","author":"SnowX"},{"number":489,"title":"`Lender::liquidate()` can leave debt position size below `minDebt`, creating in dust position with no liquidation incentive","author":"AlexCzm"},{"number":495,"title":"Interest accrual can permanently freeze after long downtime due to division by zero in InterestModel","author":"kode-n-rolla"},{"number":496,"title":"Attacker will steal all borrower collateral for free via writeOff() during oracle staleness","author":"joshuam33"},{"number":499,"title":"Liquidator will seize all borrower collateral at near-zero price after oracle staleness","author":"arunabha003"},{"number":506,"title":"Redeem reverts on final free-debt wei, permanently DoSing redemptions","author":"x15"},{"number":508,"title":"Stale Oracle Allows Full Collateral Seizure with Partial Repayment and Debt Socialization","author":"Psycharis"},{"number":509,"title":"Liquidations stay on during stale oracle, enabling near-zero-price collateral grabs.","author":"x15"},{"number":510,"title":"Hardcoded PSM Exchange Rate (1:1 Assumption)","author":"desaperh"},{"number":512,"title":"[High] Stale oracle makes all collateral liquidatable at ~zero price","author":"0xc0ffee1"},{"number":513,"title":"writeOff() is externally callable, allowing free collateral extraction and forced bad\u2011debt redistribution","author":"DevMukhtar"},{"number":515,"title":"Inconsistent Unit Semantics in adjust() Cause API Confusion and Incorrect Collateral Accounting","author":"0xHexed"},{"number":516,"title":"Stale oracle data lets attackers seize borrower collateral via write-offs or near-free liquidations","author":"theholymarvycodes"},{"number":521,"title":"Lender interest can be stolen by manipulating vault's totoalStaked","author":"h2134"},{"number":523,"title":"H-02 - updateBorrower Loop Cap","author":"0xNihilo"},{"number":527,"title":"M-04 - nonRedeemableCollateral Desync","author":"0xNihilo"},{"number":534,"title":"Accrued PSM profit creates unbacked stablecoin supply on subsequent vault losses","author":"algiz"},{"number":537,"title":"Protocol Insolvency due to `updateBorrower` Loop Limit and Incorrect State Synchronization","author":"coin2own"},{"number":538,"title":"Missing Check for Chainlink Oracle `minAnswer`/`maxAnswer` Leads to Collateral Overvaluation","author":"coin2own"},{"number":540,"title":"PSM Depeg Arbitrage Drains Borrower Collateral Violating Risk Isolation","author":"OxNoble"},{"number":541,"title":"Borrower Can Self-Call writeOff() to Evade Liquidation and Extract Collateral Without Repayment","author":"jayjoshix"},{"number":542,"title":"Fully-stale Chainlink feed enables near-free liquidation because `getCollateralPrice()` keeps `allowLiquidations = true` while forcing `price = 1`","author":"legat"},{"number":545,"title":"USDT Incompatibility Leads to Deployment DoS and Broken Functionality for PSM Vaults","author":"coin2own"},{"number":548,"title":"Stale price data allows unfair liquidations and redemptions with incorrect prices","author":"cheng"},{"number":550,"title":"Fully-stale oracle enables collateral theft via `writeOff()` due to `allowLiquidations` staying true while price is clamped to 1","author":"legat"},{"number":551,"title":"`Lender.adjust` doesn't scale  `collateralDelta` to 18 decimals when `collateralDelta < 0`","author":"ck"},{"number":553,"title":"Chainlink Oracle will return the wrong price for asset if underlying aggregator hits minPrice","author":"MoZi"},{"number":556,"title":"accrueInterest() / getPendingInterest() use fragile gas-based require in catch \u2192 view functions (e.g. Vault.totalAssets()) can revert, violating EIP-4626 \u201cMUST NOT revert\u201d and causing unexpected failures for integrators.","author":"Xmanuel"},{"number":557,"title":"Operator Can Steal All User Collateral When Collateral Token Equals PSM Asset","author":"OxNoble"},{"number":558,"title":"Inconsistent Parameter Units in `adjust` Function Causes Fund Lock","author":"coin2own"},{"number":561,"title":"`Write-off()` transfers collateral to caller instead of redistributing, expanding bad debt","author":"cheng"},{"number":562,"title":"Free debt borrower can avoid collateral redemptions through debt status switchings","author":"h2134"},{"number":564,"title":"Stale PSM Profit in Free Debt Ratio Calculation","author":"PeterSR"},{"number":566,"title":"reapprovePsmVault function fails with USDT-like tokens causing permanent DOS of PSM functionality","author":"anchabadze"},{"number":567,"title":"Stale oracle unwind clamps collateral price to `1`, enabling near-free redemptions (collateral drain) and breaking `nonRedeemableCollateral` accounting (redeem DoS)","author":"unineko"},{"number":568,"title":"freePsmAssets variable becomes stale as PSM vault accrues yield leading to incorrect protocol calculations","author":"anchabadze"},{"number":569,"title":"Incorrect Decimal Trust in adjust() Allows User-Favorable Collateral Extraction and Silent Accounting Corruption","author":"theholymarvycodes"},{"number":571,"title":"writeOff Debt Redistribution Front-Running","author":"SnowX"},{"number":573,"title":"Stale Oracle Redemption Drain","author":"vivekd"},{"number":575,"title":"Free debt borrowers can prevent redemption risk","author":"0xc0ffEE"},{"number":576,"title":"PSM buy() Function Permanently Disabled After Immutability Deadline Breaking Peg Stability","author":"OxNoble"},{"number":577,"title":"Borrowers will game redemptions by toggling isRedeemable instantly, either dodging forced redemptions or JIT-capturing redemption spread from honest borrowers","author":"al0x23"},{"number":579,"title":"Liquidations/redemptions can be performed with stale prices","author":"0xeix"},{"number":580,"title":"Stale Oracle Decay Enables Liquidations at Artificial Price of 1 Wei","author":"0xMosh"},{"number":581,"title":"Liquidations Not Paused When Oracle Price Is Decayed to Zero Due to Staleness","author":"cd_pandora"},{"number":582,"title":"Liquidation Reentrancy Drain","author":"vivekd"},{"number":585,"title":"Critical Oracle Staleness Enables Collateral Theft via writeOff Self-Liquidation","author":"OxNoble"},{"number":586,"title":"Attacker will steal all collateral from severely undercollateralized borrowers through unrestricted writeOff function","author":"Opecon"},{"number":593,"title":"PSM Vault Losses Permanently Inflate Interest Rate Calculations for All Borrowers","author":"xxiv"},{"number":594,"title":"Vault Violates EIP-4626 MUST NOT Revert Requirement","author":"edger"},{"number":596,"title":"Liquidators lose money on full liquidations due to flawed collateral reward capping logic.","author":"typicalHuman"},{"number":597,"title":"Insufficient validation of liquidation amount leads to unprofitable debt accumulation.","author":"typicalHuman"},{"number":598,"title":"Attacker will drain all collateral from the Lender","author":"philps007"},{"number":599,"title":"Staleness checks return non-zero price instead of disallowing all operations when the data is too stale","author":"0xeix"},{"number":602,"title":"```getCollateralPrice()``` Can Zero Out Price While allowLiquidations Remains True, Allowing Protocol-Wide Collateral Theft","author":"theholymarvycodes"},{"number":605,"title":"Price staleness allows unfair liquidations","author":"h2134"},{"number":606,"title":"Staleness checks incorrectly decrease the price of collateral instead of setting flags to false","author":"0xeix"},{"number":608,"title":"ERC4626 Deposit Event/Return Mismatch on First Deposit","author":"vivekd"},{"number":610,"title":"Liquidations become unprofitable at LTV > 400% preventing cleanup until LTV > 10000%","author":"blockace"},{"number":611,"title":"ERC-4626 non-compliance as totalAssets() depends on external call that may revert","author":"algiz"},{"number":612,"title":"Rounding errors when calculating the buying fee will lead to the protocol losses","author":"0xeix"},{"number":614,"title":"Interest Accrual Can Be Permanently Skipped After Long Inactivity via Overflow-Guard \u201cSuccess\u201d Path","author":"Edoscoba"},{"number":615,"title":"Attacker will drain all collateral from Lender when oracle is stale","author":"eloujoe"},{"number":619,"title":"Off-by-one error when calculating the fees with current == deadline time","author":"0xeix"},{"number":620,"title":"adjust() accepts collateral deltas in inconsistent units","author":"vivekd"},{"number":623,"title":"Losses by PSM vault are suffered only by the last withdrawers.","author":"tedox"},{"number":625,"title":"Stale Oracle Results in Protocol-Wide Collateral Drain","author":"SOPROBRO"},{"number":629,"title":"Stale Oracle Price Can Enable Liquidations that Seize All Borrower Collateral","author":"Matin"},{"number":630,"title":"Immutable Collateral Factor Contradicts Operator Adjustment Requirements","author":"edger"},{"number":633,"title":"Operator Role Can Be Modified After Immutability Deadline","author":"edger"},{"number":634,"title":"Oracle Staleness Liquidation Mega-Discount","author":"SnowX"},{"number":635,"title":"Stale Price Arbitrage & Collateral Draining","author":"songyuqi"},{"number":638,"title":"Interest accrual to unowned min shares causes protocol loss","author":"X0sauce"},{"number":640,"title":"Users can front-run redemptions by switching to paid debt and switch back to benefit from near-zero interest rates","author":"magickenn"},{"number":645,"title":"Stale Oracle Price Allows Unfair Liquidations","author":"5am"},{"number":646,"title":"Yield redirection via spot vault balance manipulation allows attacker to drain additional local protocol reserve fees","author":"al0x23"},{"number":648,"title":"Oracle staleness forces near-zero price enabling mass liquidations, write-offs, and cheap redemptions","author":"edger"},{"number":651,"title":"The decimal precision of internalAmount in the adjust function is inconsistent","author":"coffiasd"},{"number":652,"title":"Redeemers will drain PSM liquidity from PSM users when collateral equals PSM asset","author":"eloujoe"},{"number":656,"title":"writeOff() Allows Premature Collateral Seizure Without Enforcing Prior Liquidation as it is permissionless.","author":"0xHexed"},{"number":660,"title":"Division by Zero in redeem Function Leads to Denial of Service","author":"5am"},{"number":661,"title":"Sell can revert when PSM accounting is stale (`freePsmAssets` lags actual redeemable assets) - DoS","author":"edger"},{"number":662,"title":"acceptOperator() will cause state inconsistency for the protocol as it will not reset pendingOperator to zero","author":"Umesh1145"},{"number":663,"title":"[CRITICAL] Lazy Share Updates in updateBorrower() Enable Profitable Redemption Loop Extracting 20% of Deposited Collateral","author":"Zee99y"},{"number":665,"title":"Users can get liquidated even if they shouldn't according to the price","author":"Kalogerone"},{"number":669,"title":"Missing accrueInterest call after updating customFee and  feeBps","author":"SarveshLimaye"},{"number":670,"title":"Stale PSM profit not realized before interest accrual misprices rates/fees","author":"edger"},{"number":671,"title":"Free-debt borrowers will avoid redemptions, shifting losses onto other borrowers","author":"0xapple"},{"number":674,"title":"Operator role remains mutable after immutability deadline","author":"eloujoe"},{"number":675,"title":"Linear price decay during oracle staleness allows liquidation of users' healthy positions","author":"Meoww"},{"number":676,"title":"MEV Front-Running Enables Debt Socialization Avoidance Transferring Losses to Remaining Users","author":"OxNoble"},{"number":678,"title":"Stale oracle allows redemptions at near-zero price, draining protocol collateral","author":"MissDida"},{"number":682,"title":"Intentional Division-by-Zero in redeem() Can Unexpectedly Revert User Redemptions","author":"Rocky_14"},{"number":684,"title":"If a borrower misses more than 5 epochs there is no way to apply redemption for the other missed epochs","author":"Valves"},{"number":686,"title":"Deposit event emits incorrect shares amount for first deposit violating EIP-4626 standard","author":"anchabadze"},{"number":688,"title":"Unfair Liquidation  Due to Stale Oracle Price","author":"futureHack"},{"number":691,"title":"Front-running bad debt event can increase losses for other users","author":"Valves"},{"number":697,"title":"Attacker can steal borrowers\u2019 collateral during oracle staleness by abusing liquidation/writeOff/redemption logic","author":"0xSam"},{"number":698,"title":"Redemption mechanism can be griefed by front-running","author":"iamthesvn"},{"number":699,"title":"Stale oracle prices still allow liquidations, causing borrowers to be unfairly liquidated","author":"deadmanwalking"},{"number":702,"title":"Stale oracle price enables underpriced liquidations and redemptions","author":"HonorLt"},{"number":704,"title":"A user can steal all collateral from borrowers during extended oracle staleness","author":"xxiv"},{"number":705,"title":"Oracle Staleness Enables Mass Liquidation At Artificially Inflated Prices","author":"0xheartcode"},{"number":706,"title":"The Function `redeem()` Cannot Clear the Last Free Debt Due to Intentional Division-by-Zero","author":"Matin"},{"number":708,"title":"Redemptions still function with stale, decayed oracle prices, enabling mispriced collateral redemptions and peg risk","author":"deadmanwalking"},{"number":711,"title":"`totalAssets` can revert and break one of the MUST statements of ERC-4626.","author":"holtzzx"},{"number":712,"title":"Liquidation allowed on stale price (oracle staleness \u2192 underpriced liquidations)","author":"pindarev"},{"number":713,"title":"Liquidation Reentrancy Drains Other Users\u2019 Collateral","author":"Edoscoba"},{"number":715,"title":"Certain actions should be immutable after deadline, but they're not.","author":"bughuntoor"},{"number":720,"title":"Missing Chainlink minAnswer/maxAnswer bounds check can overvalue collateral during flash crashes","author":"deadmanwalking"},{"number":722,"title":"Stale `freePsmAssets` values cause incorrect free debt ratio calculations","author":"Silvermist"},{"number":723,"title":"Global Fee Updates Are Applied One Accrual Late Causing Systematic Fee Under-Collection","author":"Matin"},{"number":725,"title":"Wrong decrease of the `freePsmAssets` in the `sell` function","author":"4th05"},{"number":733,"title":"Liquidation of an under-collateralized position may occur despite the collateral's price being stale","author":"0xpiken"},{"number":735,"title":"Losses in `psmVault` or a depeg of `psmAsset` will make Coin undercollateralized and cause depeg","author":"deadmanwalking"},{"number":736,"title":"Inconsistent Half-Life Bounds Will Enable Post-Deployment Interest Rate Acceleration","author":"Matin"},{"number":737,"title":"Missing zero-check in `Lender::redeem` epoch transition logic causes permanent DoS of redemption functionality","author":"makeWeb3safe"},{"number":746,"title":"Unfair liquidations during oracle staleness due to aggressive price decay","author":"ubl4nk"},{"number":750,"title":"Attacker will seize most borrower collateral for negligible repayment  from  undercollateralized borrowers.","author":"NovaTheMachine"},{"number":751,"title":"`minTotalSupply` check permanently blocks `buy()` unless PSM vault is manually seeded","author":"cyberEth"},{"number":754,"title":"Users Can Sandwich Redemptions to Avoid Collateral Loss While Maintaining Free Debt","author":"molaratai"},{"number":756,"title":"totalAssets can revert and violate EIP","author":"0xGondar"},{"number":760,"title":"PSM Vault Loss Not Reflected in freePsmAssets Leading to Hidden Insolvency","author":"ubl4nk"},{"number":762,"title":"Buy fees will be off by 7 more days even after half time(second half).","author":"asui"},{"number":770,"title":"Stale Oracle Price Fallback to 1 Allows Unfair Liquidations","author":"0x97"},{"number":771,"title":"Malicious borrower can escape the incoming bad debt distribution during write-off.","author":"Ocean_Sky"},{"number":780,"title":"writeOff() Lets Any Caller Seize Collateral Without First Going Through Liquidation","author":"theholymarvycodes"},{"number":787,"title":"External Actor Will Steal Residual Collateral Due to Unrestricted WriteOff Access","author":"francoHacker"},{"number":788,"title":"PSM traders will suffer systematic mispricing and yield extraction due to stale freePsmAssets accounting","author":"0xkb"},{"number":791,"title":"Oracle Staleness Allows Liquidation at 1 Wei Price","author":"Theseersec"},{"number":792,"title":"Attacker will withdraw collateral that should have been consumed by prior redemptions harming other redeemable borrowers (collateral shortfall).","author":"NovaTheMachine"},{"number":793,"title":"writeOff Can Be Frontrun to Steal Collateral","author":"Theseersec"},{"number":797,"title":"Collateral draining via PSM asset/collateral confusion in `accruePsmProfit()`","author":"Bobai23"},{"number":799,"title":"Incorrect Free Debt Ratio Calculation Due to Unaccounted PSM Profit Accrual","author":"Bobai23"},{"number":802,"title":"Liquidation uses an unrealistically low price on stale oracle data that leads to borrower\u2019s unexpected loss","author":"harry"},{"number":804,"title":"Oracle Staleness Unwind Allows Liquidations at Artificially Depressed Prices","author":"rj_eth26"},{"number":809,"title":"ERC4626 PSM accounting drift enables phantom profit minting and sell-side denial of service","author":"Valves"},{"number":816,"title":"Liquidations can lead to accumulation of dust debt amounts below the `minDebt` value","author":"ck"},{"number":817,"title":"`freePsmAssets` parameter reflects incorrect value as the losses are not reported","author":"0xeix"},{"number":818,"title":"Oracle Staleness Mechanism Creates Arbitrage Opportunity for Protocol Drainage","author":"0xscater"},{"number":822,"title":"setRedemptionStatus is lack of cooldown mechanism","author":"coffiasd"},{"number":823,"title":"Protocol will lose fees during a sell function call","author":"typicalHuman"},{"number":824,"title":"adjust() Enforces Inconsistent Unit Types for Deposits vs. Withdrawals, Causing Fund Loss and Integration Failure","author":"0xscater"},{"number":827,"title":"Incorrect account of collateral in `adjust` function when `collateralDelta` is negative","author":"SarveshLimaye"},{"number":828,"title":"Protocol is not fully immutable after immutability deadline","author":"typicalHuman"},{"number":829,"title":"Loss of funds due to no access control on `Lender::writeOff`, which is supposed to be called internally or by contract itself.","author":"argon"},{"number":831,"title":"Bypass of MIN_LIQUIDATION_DEBT or Total User Debt Enforcement Allows Creation of Bad Debt Through Partial Liquidations","author":"Bobai23"},{"number":833,"title":"Oracle Heartbeat Boundary Causes Catastrophic Price Mispricing","author":"futureHack"},{"number":835,"title":"Protocol's staleness handling allows liquidations at artificially low price.","author":"Ocean_Sky"},{"number":849,"title":"Protocol allows liquidators to liquidate borrowers for very small amounts, bypassing the MIN_LIQUIDATION_DEBT restriction.","author":"typicalHuman"},{"number":851,"title":"Borrowers can lose collaterals in case PSM asset/vault is depegged","author":"0xc0ffEE"},{"number":852,"title":"Liquidators can leave less than `minDebt` amount in liquidated positions allowing for bad debt accumulation","author":"0xeix"},{"number":858,"title":"Operator cannot adjust collateral factor, liquidation parameters, or PSM fees","author":"0xShoonya"},{"number":862,"title":"Redemptions and Liquidations are enabled at artificially low prices when oracle returns stale prices","author":"dic0de"},{"number":864,"title":"Stale oracle allows liquidation while blocking position improvements","author":"X0sauce"},{"number":887,"title":"PSM profit accounting fails when collateral and PSM asset are the same","author":"h2134"},{"number":890,"title":"Borrower state update logic incorrectly skips epochs due to loop limit, allowing evasion of slashing and debt accrual","author":"oxGan1"},{"number":892,"title":"stale \u2260 liquidations disabled: liquidations are not disabled under oracle staleness, contradicting documented safety guarantees","author":"BroRUok"},{"number":895,"title":"EIP-4626 compliance broken","author":"0xsh"},{"number":896,"title":"Oracle Staleness Logic Incompatible with Forex Market Price Feed, Leading to Unfair Liquidations","author":"0xbzbee42"},{"number":897,"title":"Public write off allows free collateral extraction during price spikes","author":"X0sauce"},{"number":899,"title":"Incompatibility when PSM asset is USDT","author":"0xc0ffEE"},{"number":902,"title":"Unfair Liquidations Due to Extreme Price Staleness Not Disabling Liquidations","author":"Sneks"},{"number":903,"title":"Privileged roles remain changeable post-deadline, breaking immutability promise","author":"h2134"},{"number":904,"title":"First depositor will cause ERC-4626 `Deposit` event to emit erroneous amount of minted shares, breaking ERC-4626 compliance for integrator","author":"web3made"},{"number":907,"title":"`allowLiquidations` should be `false` for stale prices","author":"whitehair0330"},{"number":909,"title":"Forced Write-Off via Stale Oracle Exploitation (Stale Price Logic failure leads to Total Protocol Drain)","author":"ZeronautX"},{"number":910,"title":"updateBorrower() assigns global epoch instead of processed epoch, allowing borrowers to skip redemption deductions","author":"Sir_Shades"},{"number":915,"title":"`##Lender::sell` subtracts the `freePsmAssets` with incorrect amount","author":"hard1k"},{"number":916,"title":"USDT as psmAsset approve failures make Lender markets unusable","author":"harry"},{"number":917,"title":"Liquidations Proceed Using Synthetic wrong Price After Full Oracle Staleness","author":"aua_oo7"},{"number":918,"title":"Unrestricted writeOff Access (Lack of Access Control allows Permissionless Theft)","author":"ZeronautX"},{"number":921,"title":"PSM Losses Not Updated","author":"Theseersec"},{"number":922,"title":"Anyone can call writeOff() lead to breaking protocol invariant(mint stablecoin without backing by collateral) and wrong liquidation","author":"aua_oo7"},{"number":924,"title":"Liquidation Re-entrancy State Overwrite (Checks-Effects-Interactions Violation leads to Double Spend)","author":"ZeronautX"},{"number":929,"title":"MIN_LIQUIDATION_DEBT is not enforced as an actual minimum repay amount","author":"dantehrani"},{"number":930,"title":"Psm asset approval incompatibility with USDT","author":"X0sauce"},{"number":931,"title":"PSM \"Kill Switch\" Time-Bomb (Immutability Deadline permanently disables Buy function)","author":"ZeronautX"},{"number":933,"title":"Oracle fallback forces `price = 1`, while keeping liquidations enabled, enabling severe mispricing.","author":"0xpetern"},{"number":934,"title":"Partial Liquidation Can Leave Residual Debt With No Liquidation Incentive","author":"futureHack"},{"number":935,"title":"Lazy Redemption Epoch Skip (Unconditional Epoch Jump allows Penalty Evasion)","author":"ZeronautX"},{"number":937,"title":"Coin usd parity assumption in solvency checks","author":"X0sauce"},{"number":945,"title":"An attacker will steal borrowers\u2019 collateral for free during oracle staleness","author":"DSbeX"},{"number":946,"title":"PSM-backed minting does not reconcile on underlying losses, causing under-backed Coin and stuck redemptions","author":"Cara"},{"number":947,"title":"PSM Accounting Drift (Sync mismatch between Expected and Actual Asset Out)","author":"ZeronautX"},{"number":948,"title":"Reentrancy in `liquidate()` Allows Collateral Theft via Cross-Function Attack","author":"PowPowPow"},{"number":951,"title":"Inconsistent `collateralDelta` Units in `adjust()` Causes User Fund Loss","author":"PowPowPow"},{"number":955,"title":"Reentrancy in `redeem()` Causes Double Epoch Increment and Share Corruption","author":"PowPowPow"},{"number":956,"title":"Precision Loss in getBuyFeeBps() Causes Non-Linear Fee Growth and Up to 50% Protocol Revenue Loss","author":"ephraim"},{"number":958,"title":"getCollateralPrice() can return a price of 1 without disabling liquidations which allows collateral to be stolen.","author":"ADM_"},{"number":959,"title":"Liquidate Function Re-entrancy (Systemic CEI Violation)","author":"ZeronautX"},{"number":964,"title":"Mixed Decimal Units in adjust() Function","author":"ZeronautX"},{"number":965,"title":"Stale Oracle Price Clamped to 1 While Liquidations Remain Enabled Allows Abusive Zero-Price Liquidations and Write-Offs","author":"elyas"},{"number":971,"title":"Hardcoded Loop Limit allows \"Double Spend\" of Collateral via Flash Loan Epoch Stuffing","author":"befree3x"},{"number":972,"title":"PSM sell function accounting mismatch with ERC4626 vault redemptions","author":"Cara"},{"number":973,"title":"Last Redeemer Cannot Exit (Division by Zero)","author":"ZeronautX"},{"number":975,"title":"Non-Compliance with EIP-4626 Deposit and Mint Requirements","author":"yaioxy"},{"number":976,"title":"Oracle staleness enables unfair liquidations and write-offs of healthy positions","author":"yovchev_yoan"},{"number":978,"title":"Missing Access Control in `writeOff()` Function","author":"unique"},{"number":979,"title":"Minimum debt invariant can be violated by liquidations / write-offs","author":"Cara"},{"number":981,"title":"Stale oracle prices incorrectly enable liquidations and bad debt socialization","author":"mladenov"},{"number":983,"title":"Accounting confusion when psmAsset equals collateral leads to fund loss","author":"anchabadze"},{"number":1001,"title":"Stale Price Linear Decay Causes Unfair Liquidation","author":"cht"},{"number":1002,"title":"User Can Self-Write-Off Debt and Steal Collateral via `writeOff()` Function","author":"Sneks"},{"number":1008,"title":"Liquidator will seize disproportionately cheap collateral from borrowers during oracle outages","author":"axelot"},{"number":1010,"title":"Stale price allows excessive collateral extraction during redemptions","author":"X0sauce"},{"number":1011,"title":"Redemption Front-Running allows Whales to force 100% of collateral seizure onto minority Free Debt holders","author":"hirusha"},{"number":1013,"title":"Redemption Frontrunning Attack via Instant Status Switching","author":"00001111"},{"number":1017,"title":"Oracle staleness enables redemption at artificially reduced prices","author":"mladenov"},{"number":1020,"title":"Stale oracle sets price to 1, enabling near-zero-price liquidations","author":"0xnija"},{"number":1025,"title":"PSM vault yield not reflected in interest rate calculations causing borrowers to overpay","author":"anchabadze"},{"number":1026,"title":"An attacker will drain nearly all redeemable collateral for negligible cost by exploiting oracle staleness mispricing","author":"Blackdruid"},{"number":1027,"title":"Chainlink Oracle Missing Critical Validation Checks Allows Protocol Insolvency","author":"PowPowPow"},{"number":1029,"title":"Interest Accrual Can Be Permanently Skipped Due to Overflow Protection","author":"Umesh1145"},{"number":1034,"title":"Partial Liquidations Create Bad Debt (Dust Positions)","author":"cht"},{"number":1038,"title":"PSM Vault Losses Are Not Reflected in `freePsmAssets` Leading to Inflated Accounting and Interest Rate Miscalculation","author":"PowPowPow"},{"number":1041,"title":"Oracle Staleness Allows Liquidations at Artificially Low Prices","author":"PowPowPow"},{"number":1053,"title":"`Coin` depeg will cause false liquidations for borrowers","author":"0xdoichantran"},{"number":1055,"title":"Liquidation reward assumes 1 Coin == 1 USD, causing a lower liquidation incentive when Coin deviates from peg or due to redemption fees, making liquidations potentially unprofitable","author":"deadmanwalking"},{"number":1059,"title":"Stale oracle feed allows for theft of funds due to gradual reduction of price","author":"vanshika"},{"number":1061,"title":"Inconsistent freePsmAssets Accounting Causes Inflation Leading to Incorrect Interest Rate Calculations","author":"molaratai"},{"number":1062,"title":"Instant setRedemptionStatus() enables same-block redemption evasion via debt-type toggling","author":"web3made"},{"number":1063,"title":"Vault.totalAssets() can revert violating EIP-4626\u2019s totalAssets MUST NOT revert requirement","author":"dantehrani"},{"number":1065,"title":"Wrong interest accrual due to use of stale `freePsmAssets` value","author":"SarveshLimaye"},{"number":1067,"title":"Redeemer can never fully clear free debt due to division by zero in `redeem`","author":"Diavolo"},{"number":1078,"title":"Untracked ERC4626 Vault Losses in `freePsmAssets` Accounting Causes System Undercollateralization and Unfair Loss Distribution","author":"KrisRenZo"},{"number":1079,"title":"Missing `beforeDeadline` Modifier on Operator Transfer Functions Allows Permanent Operator Mutability","author":"KrisRenZo"},{"number":1083,"title":"Immutability Deadline Can Be Bypassed for Operator and Manager Roles","author":"elyas"},{"number":1098,"title":"Interest Calculation Overflow Protection Returns Zero Interest, Permanently Freezing Accrual","author":"makeWeb3safe"},{"number":1101,"title":"Attacker can liquidate healthy borrower positions when oracle becomes stale","author":"kode-n-rolla"},{"number":1105,"title":"PSM vault losses cause `freePsmAssets` to drift upward, overstating `getFreeDebtRatio()` and under-accruing interest on paid debt","author":"legat"},{"number":1108,"title":"Hardcoded iteration limit in updateBorrower causes incomplete epoch updates for inactive borrowers","author":"anchabadze"},{"number":1110,"title":"Protocol will permanently halt when last redeemer triggers division by zero","author":"0xzulkifilu"},{"number":1111,"title":"The protocol allows bad debt to be distributed before liquidation occurs, which makes the distribution consequences more severe for all borrowers.","author":"typicalHuman"},{"number":1112,"title":"Liquidation can create invalid debt positions below minDebt","author":"h2134"},{"number":1117,"title":"Oracle staleness exploitation allow liquidations at artificial price","author":"0xShoonya"},{"number":1119,"title":"freePsmAssets Not Updated on Vault Loss Causes Accounting Mismatch and sell() Function Denial of Service","author":"Zee99y"},{"number":1120,"title":"maxBorrowDeltaBps cannot be set in the 2.0% - 5.0% range as intended","author":"prk0"},{"number":1121,"title":"Solvent Users Liquidated at Unfair Prices due to Oracle Staleness - Linear Decay","author":"hirusha"},{"number":1123,"title":"Decreasing collateral value based on price staleness will result in unfair losses.","author":"bughuntoor"},{"number":1125,"title":"If `psmVault` takes a loss, stablecoin will be permanently unbacked.","author":"bughuntoor"},{"number":1126,"title":"Operator role remains mutable after immutability deadline contrary to README","author":"deadmanwalking"},{"number":1128,"title":"The requirement in the constructor regarding `halfLife` bypassed.","author":"4th05"},{"number":1129,"title":"Missing update of the `allowLiquidations` parameter in case of stale prices calling `getCollateralPrice`","author":"4th05"},{"number":1130,"title":"Interest Model Division-By-Zero on Long Dormancy","author":"ZeronautX"},{"number":1131,"title":"Oracle Staleness \"Safety Mechanism\" enables Arbitrage Looting during Feed Downtime","author":"befree3x"},{"number":1132,"title":"Incorrect Staleness Check in Redemption Function Allows Users to Extract Excess Collateral","author":"yovchev_yoan"},{"number":1134,"title":"Borrower can sandwich redemptions by toggling redemption status to avoid collateral seizure while remaining interest-free","author":"deadmanwalking"},{"number":1137,"title":"PSM Vault Losses Not Recognized, Breaking Peg Maintenance During Market Stress","author":"shieldrey"},{"number":1138,"title":"Redemptions, Status Changes, and Partial Liquidations Bypass minDebt Enforcement Creating Bad Debt Risk","author":"KrisRenZo"},{"number":1146,"title":"`Approve()` will revert leading DOS","author":"xiaoming90"},{"number":1148,"title":"Immutable Collateral Factor Declaration Prevents Documented Parameter Adjustments and Eliminates Critical Risk Management Capability","author":"KrisRenZo"},{"number":1154,"title":"Borrowers Can Self-Execute Write-Offs to Claim Collateral Rewards While Socializing Debt Losses to Other Borrowers","author":"KrisRenZo"},{"number":1157,"title":"Incorrect Oracle Price Handling Allows Unauthorized Write-Offs","author":"Sneks"},{"number":1162,"title":"Absence of Exit Restrictions During Bad Debt Events Enables Unfair Loss Distribution Among Protocol Users","author":"KrisRenZo"},{"number":1163,"title":"Liquidators will steal collateral from healthy borrowers","author":"basia"},{"number":1164,"title":"Stale Global Fee Usage During Interest Accrual Causes Protocol Revenue Loss","author":"KrisRenZo"},{"number":1168,"title":"Absence of Loss-Bearing Requirement in writeOff Function Enables Attackers to Extract Collateral Value While Socializing Bad Debt to Protocol Depositors","author":"KrisRenZo"},{"number":1170,"title":"Fee changes not applied instantly leading to loss of yield for globalFee recipient","author":"heavyw8t"},{"number":1184,"title":"Limited Epoch Catch-Up Loop in `updateBorrower()` Allows Redeemable Borrowers to Skip Collateral Redemptions","author":"KrisRenZo"},{"number":1186,"title":"Users can avoid redemptions without paying interest by sandwiching them with `setRedemptionStatus`","author":"dandan"},{"number":1187,"title":"The `psmAsset` doesn't have a chainlink feed","author":"Kalogerone"},{"number":1188,"title":"`Vault.totalAssets()` may revert","author":"dandan"},{"number":1189,"title":"Stale oracle allows liquidating borrowers at absurd price","author":"dandan"},{"number":1190,"title":"Operator/Manager can be changed after immutability deadline","author":"dandan"},{"number":1191,"title":"Inconsistent `halfLife` validation allows setting values below constructor minimum","author":"Silvermist"},{"number":1193,"title":"A stale oracle can cause assets to be drained","author":"xiaoming90"},{"number":1195,"title":"PSM reserves can be drained via redeem() when psmAsset == collateral and no PSM vault is used","author":"dantehrani"},{"number":1196,"title":"Debt share prices can decrease due to `increaseDebt()` math","author":"xiaoming90"},{"number":1197,"title":"Vault's `totalAssets()` breaks ERC4626 compliance by reverting on insufficient gas","author":"cholakovvv"},{"number":1200,"title":"Stale oracle floors price to 1 but still allows liquidations, letting attacker drain collateral","author":"Funen"},{"number":1201,"title":"Stale `freePsmAssets` values cause incorrect free debt ratio calculations","author":"Silvermist"},{"number":1211,"title":"Immediate debt redistribution will cause unfair loss allocation for borrowers as sophisticated users will time entry and exit to avoid inheriting bad debt","author":"0xHexed"},{"number":1212,"title":"Stale oracle decay forces an invalid price enabling unfair liquidations and redemptions at that price","author":"iamephraim"},{"number":1217,"title":"In the contract `Lender.sol` there is loss of fee every time when fee update","author":"Himanshu772005"},{"number":1222,"title":"Oracle Staleness Logic can Cause all Collateral to be Stolen by an Attacker","author":"uuzall"},{"number":1223,"title":"Contract allows ```sell``` without applying PSM losses, which will leave unredeemable coins in the system.","author":"asui"},{"number":1224,"title":"Permissionless `writeOff()` Enables Arbitrary Collateral Theft","author":"rj_eth26"},{"number":1227,"title":"Factory fee changes are not applied during the next interest accrual","author":"Negin"},{"number":1233,"title":"collateral will be mis-accounted as psm profit when psmAsset == collateral and psmVault is unset, enabling unintended rprofit via the psm reserve flow.","author":"AestheticBhai"},{"number":1241,"title":"PSM vault sell rounding causes `freePsmAssets` desync, skewing interest rates and enabling excess reserve minting","author":"heavyw8t"},{"number":1243,"title":"psmAsset is assumed to have 1 USD value","author":"0rpse"},{"number":1247,"title":"'Free debt' borrower can avoid collateral reduction by sandwiching incoming redeem() transactions","author":"d33p"},{"number":1250,"title":"Deposit event misreports shares on first mint (EIP-4626 Deposit event MUST violation)","author":"greekfreakxyz"},{"number":1251,"title":"Healthy positions are unfairly liquidated during oracle staleness due to missing liquidation protection","author":"PolarizedLight"},{"number":1252,"title":"Unrestricted `writeOff` Allows Arbitrary Third Parties to Seize Collateral of Severely Undercollateralized Positions","author":"Zabid27"},{"number":1253,"title":"totalAssets/convert/preview can revert due to gas floor (EIP-4626 MUST-not-revert violation)","author":"greekfreakxyz"},{"number":1254,"title":"A user can avoid bad debt socialization by frontrunning debt repayment transactions.","author":"0xpiken"},{"number":1257,"title":"coin seller will experience a denial of service as the protocol will revert sell operations","author":"CovenantGuard_Sec"},{"number":1264,"title":"Missing Logic for Losses in PSM Vaults Causes Interest Accrual to be Incorrectly Calculated","author":"uuzall"},{"number":1265,"title":"Decimal Mismatch in `adjust()` Causes Collateral Loss for Non-18-Decimal Tokens","author":"Nyxx"},{"number":1270,"title":"fee lost on buy() because of low presicion usage","author":"moray5554"},{"number":1271,"title":"Liquidation create bad position due to Minimum Amount Not Enforced, logic flaw in liquidation function.","author":"LonWof-Demon"},{"number":1273,"title":"Stale Oracle Exploitation via writeOff and liquidate","author":"makarov"},{"number":1276,"title":"Critical DoS: Redeem Function Division by Zero - Last Redemption Always Fails","author":"Macbughunter"},{"number":1279,"title":"Anyone Can Steal Collateral via writeOff Without Repayment","author":"shieldrey"},{"number":1283,"title":"MEV Vulnerability: Redemption Status Frontrunning Enables Sophisticated Users to Escape Redemption Costs","author":"Wolf_Kalp"},{"number":1285,"title":"Liquidator will liquidate healthy borrowers when the protocol uses a stale price","author":"CovenantGuard_Sec"},{"number":1289,"title":"ERC-4626 violation: totalAssets() can revert due to external call to lender.getPendingInterest()","author":"al0x23"},{"number":1290,"title":"liquidation still enabled when oracle is stale","author":"farismaulana"},{"number":1291,"title":"Missing Decimal Conversion in `adjust` when `collateraldelta< 0` Causes Fund Loss and DOS situations","author":"zkillua"},{"number":1298,"title":"Stale PSM Accounting Can Block Coin Selling","author":"Nyxx"},{"number":1299,"title":"Old Global Fee Cache Causes Incorrect and undfair Fee Accounting During Interest Accrual","author":"0xlucky"},{"number":1303,"title":"`buy()` cannot be used after deadline","author":"ke1caM"},{"number":1306,"title":"possible Withdrawing Before Bad Debt Event/socialize","author":"Theseersec"},{"number":1308,"title":"Oracles with very stale prices allow for extreme price deviations.","author":"tedox"},{"number":1313,"title":"Stale Price Logic Failure Allows Liquidations at Near-Zero Price","author":"ChaosSR"},{"number":1317,"title":"Liquidation of Solvent Positions Due to Use of Stale Oracle Prices","author":"LonWof-Demon"},{"number":1318,"title":"`MIN_LIQUIDATION_DEBT` doesn't work within `Lender#liquidate()`","author":"0xpiken"},{"number":1320,"title":"Stale Oracle Price Allows Liquidation of Otherwise Healthy Positions","author":"Nyxx"},{"number":1323,"title":"Oracle Staleness Liquidation: Exploitative Liquidations During Reduce-Only Mode Despite Price Protection Mechanisms","author":"Wolf_Kalp"},{"number":1327,"title":"Inconsistent Decimal Handling in adjust() Leads to Collateral Loss for Non-18-Decimal Assets","author":"LonWof-Demon"},{"number":1329,"title":"Malicious liquidators can cause bad debt to accumulate by leaving dust collateral , delaying loss  socialization .","author":"Theseersec"},{"number":1334,"title":"Redeemable borrowers will grief redeemers by toggling redemption status (front-run and back-run)","author":"Le_Rems"},{"number":1337,"title":"Inconsistent Decimal Handling in `Lender::adjust` Leads to Severe Collateral Under-Withdrawal","author":"CovenantGuard_Sec"},{"number":1339,"title":"Attacker will steal all borrower's collateral and socialize their debt","author":"Le_Rems"},{"number":1348,"title":"System can behave unexpectedly if collateral is the same as reference asset","author":"0xc0ffEE"},{"number":1352,"title":"The `getCollateralPrice` doesn't set allowLiquidation to false when the prices remain stale after stale unwind duration causing the protocol wise DoS and even insolvency","author":"Aasif"},{"number":1353,"title":"Wrong price setup leads to mega liquidations","author":"ke1caM"},{"number":1355,"title":"Collateral Withdrawal Precision Loss in adjust()","author":"Bizarro"},{"number":1360,"title":"Liquidation will happen even when the oracle price is stale","author":"ByteFable"},{"number":1361,"title":"Division by Zero in InterestModel Causes DoS","author":"khaye26"},{"number":1362,"title":"Yield/Profit of the PSM vault is not accounted in functions of Lender","author":"holtzzx"},{"number":1363,"title":"`freePsmAssets` accounting uses expected instead of actual in `sell()`","author":"0xeix"},{"number":1367,"title":"Epoch Assignment issue in updateBorrower","author":"khaye26"},{"number":1370,"title":"updateBorrower can return stale data, leading to loss of funds.","author":"5am"},{"number":1372,"title":"accruePsmProfit() does not update when there is a loss / negative rebase which causes freePsmAssets to go out of sync","author":"prk0"},{"number":1373,"title":"Minimum Liquidation Amount Not Enforced for Small Positions","author":"CovenantGuard_Sec"},{"number":1375,"title":"Instant Debt\u2011Type Toggle Enables Redemption Frontrunning","author":"rj_eth26"},{"number":1376,"title":"Stale Oracle Allows Cheap Liquidation and Collateral Theft","author":"derastephh"},{"number":1377,"title":"violation of EIP4626 compliance in event deposit","author":"slowpoke"},{"number":1380,"title":"A liquidator can repay a minimal amount of debt and seize 100% of the borrower's collateral due to the oracle stale price, even if the actual market price of the collateral implies the user is fully solvent.","author":"Riceee"},{"number":1383,"title":"Minimum Liquidation Amount Not Enforced Allows Partial Liquidation of Small Positions","author":"Nyxx"},{"number":1384,"title":"RSM\u00a0Reserves invariant broken when psmVault\u00a0experiences\u00a0losses after\u00a0profit accrual","author":"touristS"},{"number":1387,"title":"Borrowers can MEV-switch out of redeemable debt to avoid a redemption haircut","author":"Sparrow_Jac"},{"number":1388,"title":"Unit mismatch in `adjust()` withdraw path \u2014 internal 18-decimals vs token decimals leads to loss/theft for small withdrawals","author":"pindarev"},{"number":1390,"title":"Stale oracle forces price to 1 but keeps liquidations enabled, so liquidate and redeem run on a fake price","author":"emmanuel_ewah"},{"number":1395,"title":"Liquidator can extract maximal value by paying as small as 1 wei debt and take all the collateral during writeOff","author":"Riceee"},{"number":1396,"title":"Economic Risk of Permissionless Bad-Debt Socialization via writeOff() in Extreme Insolvency Scenarios","author":"aua_oo7"},{"number":1399,"title":"position can have debt Below minDebt, Violating Protocol Invariants","author":"LonWof-Demon"},{"number":1401,"title":"Liquidators will seize the borrowers' collateral at an arbitrary small price","author":"bbl4de"},{"number":1402,"title":"Interest Accrual Permanently Freezes After Extended Market Inactivity","author":"00001111"},{"number":1404,"title":"Stale Chainlink Prices may cause premature liquidations","author":"gkrastenov"},{"number":1410,"title":"Attacker Will Drain All Redeemable Collateral Through Staleness-Based Price Manipulation","author":"sourav_DEV"},{"number":1411,"title":"PSM vault profit is not accrued correctly","author":"0xc0ffEE"},{"number":1412,"title":"A Redeemer can redeem huge collateral for a small amount of debt coins when oracle price is stale","author":"Riceee"},{"number":1415,"title":"`accruePsmProfit()` is not called in `sell()`","author":"yaioxy"},{"number":1420,"title":"Free Debt Borrowers Can Evade Redemptions via Atomic Front-Running Breaking Protocol Peg Mechanism","author":"OxNoble"},{"number":1421,"title":"Redeem function contains intentional division-by-zero causing DoS on final redemption","author":"alicrali33"},{"number":1425,"title":"Redeemer Will Drain All Contract Collateral Through 36-Decimal AmountOut Calculation","author":"sourav_DEV"},{"number":1427,"title":"PSM Sell Operations Can Revert Due to Stale freePsmAssets Accounting","author":"LonWof-Demon"},{"number":1429,"title":"Long `timeElapsed` may cause interest accrual to get stuck","author":"AlexCzm"},{"number":1437,"title":"Reentrancy in liquidate leads to Protocol Insolvency","author":"hirusha"},{"number":1440,"title":"Borrower can profitably self-liquidate then trigger writeOff() to socialize remaining debt onto other borrowers","author":"Valves"},{"number":1446,"title":"Interest rate calculations use stale `freePsmAssets` value","author":"yaioxy"},{"number":1447,"title":"Missing Chainlink Circuit Breaker Validation Allows Borrowing Against Overvalued Collateral","author":"OxNoble"},{"number":1450,"title":"Cached global fee applied with one period delay causing fee losses or overpayment","author":"anchabadze"},{"number":1457,"title":"Reentrancy in `Lender.liquidate()` Can Drain Collateral","author":"kimnoic"},{"number":1464,"title":"freePsmAssets accounting inconsistency in sell() with ERC4626 vault","author":"aman"},{"number":1465,"title":"Interest accrual can freeze permanently after long inactivity","author":"Sparrow_Jac"},{"number":1468,"title":"PSM Vault loss causes stale freePsmAssets, blocking later sellers","author":"p1ramide"},{"number":1472,"title":"Vulnerability Report: Missing Price Oracle Validation in PSM Module","author":"volleyking"},{"number":1473,"title":"Unprotected decimals() call will cause deployment failure for Lender instances","author":"0xHexed"},{"number":1479,"title":"EIP\u20114626 Compliance Violations in `previewDeposit()` and `deposit()` Functions","author":"rj_eth26"},{"number":1481,"title":"Reentrancy via malicious collateral token in `Lender.liquidate()` can desync collateral accounting and overpay collateral","author":"JohnWeb3"},{"number":1482,"title":"Stale oracle handling can keep `allowLiquidations=true` while collapsing price to `1`, enabling massively underpriced redemptions/liquidations/write-offs","author":"JohnWeb3"},{"number":1483,"title":"Unrestricted `writeOff()` enables arbitrary callers to seize collateral while socializing bad debt","author":"JohnWeb3"},{"number":1487,"title":"`InterestModel.calculateInterest()` overflow-guard returns zero interest (no revert), allowing interest-free accrual intervals under extreme parameters","author":"JohnWeb3"},{"number":1495,"title":"Vault ops can be permanently DoS\u2019d if `uint120` reserve accumulators overflow (`Lender.accrueInterest()` reverts)","author":"JohnWeb3"},{"number":1497,"title":"`InterestModel.calculateInterest()` can revert on intermediate arithmetic (overflow / divide-by-zero) and `Lender.accrueInterest()` silently skips accrual without advancing `lastAccrue`","author":"JohnWeb3"},{"number":1503,"title":"PSM vault losses are ignored, leaving phantom freePsmAssets and causing wrong free debt ratio plus sell revert risk","author":"emmanuel_ewah"},{"number":1505,"title":"Deployment DoS Risk Due to Strict Reliance on decimals() for Arbitrary ERC20 Tokens","author":"theholymarvycodes"},{"number":1506,"title":"Users cannot redeem 100% of free debt: redeem() always reverts with division by zero when amountIn == totalFreeDebt","author":"0x_oi"}]}]
