[{"severity":"High","reward":34.00257089105924,"issues":[{"number":8,"title":"Fluid MoneyMarket Internal Accounting Mismatch Leads to Insolvency","author":"Wojack"},{"number":43,"title":"# Money Market Normal Withdraw Transfers Uncapped Amount from Liquidity","author":"pranamya"},{"number":46,"title":"Attacker will steal all protocol funds from other users as uncapped withdrawal amount in `_processNormalSupplyAction` allows draining MoneyMarket's Liquidity balance","author":"0xSeerBear"},{"number":101,"title":"Incorrect clamp in MoneyMarket normal withdraw allows over-withdrawal from Liquidity, leading to direct theft of pooled user funds","author":"0xastronatey"},{"number":122,"title":"MoneyMarket Withdraw Mismatch Lets Attackers Steal From Pooled Liquidity","author":"Baazigar"},{"number":263,"title":"An attacker can withdraw more tokens than their Money Market position owns, draining pooled Liquidity Layer funds from other suppliers","author":"Draxen"},{"number":282,"title":"An attacker will drain pooled liquidity from other MoneyMarket suppliers","author":"SecurityAgentOZ"},{"number":283,"title":"Incorrect Withdrawal Accounting Allows Attacker to Drain All Available Liquidity","author":"Bigsam"},{"number":289,"title":"Critical Vulnerability in Withdraw Logic of _processNormalSupplyAction","author":"0x23r0"},{"number":331,"title":"Users can make withdrawals that exceed position value","author":"lanrebayode77"},{"number":375,"title":"Attacker can withdraw more than amount supplied","author":"EddiePumpin"},{"number":390,"title":"Attacker will withdraw more than their position balance and steal pooled funds from other MoneyMarket suppliers","author":"ZeroTrust"},{"number":399,"title":"Attacker Can Drain Money Market Deposits by Withdrawing More Than Position Balance","author":"gabkov"},{"number":420,"title":"Attacker can drain Liquidity Layer funds by withdrawing more than deposited due to uncapped supplyAmount in normal withdrawal","author":"BogdanCastraveti"},{"number":445,"title":"operateModule::_processNormalSupplyAction, Attacker will withdraw excess liquidity from other users","author":"0x04"},{"number":466,"title":"Attackers can steal funds due to missing `supplyAmount_` recalculation after raw balance clamping in partial withdrawal path.","author":"0xpetern"},{"number":492,"title":"Users can steal from the protocol via normal supply positions because supplyAmount is not updated after withdraw capping","author":"elolpuer"},{"number":506,"title":"Flawed CLAMP in _processNormalSupplyAction allows user to withdraw significantly more than he supplied","author":"luc1jan"},{"number":571,"title":"Partial supply withdrawal caps raw deduction but not token amount, letting anyone drain the Liquidity pool through MoneyMarket","author":"Ridden5839"},{"number":582,"title":"Phantom / over-withdrawal via share\u2013token accounting mismatch","author":"Billy19d"},{"number":586,"title":"Malicious users can withdraw more than their supplied collateral from debt-free normal positions","author":"iamephraim"},{"number":589,"title":"Incorrect balance validation in MoneyMarket\u2019s NORMAL_SUPPLY_POSITION_TYPE enables an attacker to drain funds","author":"0xBoraichoT"},{"number":610,"title":"User can steal funds using `_processNormalSupplyAction` uncapped withdrawal","author":"0xCrypt0nite"},{"number":636,"title":"MoneyMarket Over-Withdraw via Uncapped Liquidity.operate Call","author":"maigadoh"},{"number":660,"title":"Money market depositor can withdraw more amount than they deposited draining protocol of all funds","author":"i-am-kuldeep"},{"number":673,"title":"Normal supply withdraw uses unclamped user amount for token transfer, allowing over-withdrawal beyond position balance","author":"bratwork"},{"number":686,"title":"liquidateModule::liquidate. Withdraw Settlement Uses Uncapped Token Amount After Raw Clamp","author":"0x04"},{"number":699,"title":"Attacker will steal all user funds from MoneyMarket","author":"fgh56ty"},{"number":707,"title":"MoneyMarket normal withdraw can drain pooled Liquidity via uncapped `supplyAmount_`","author":"botdidy"},{"number":712,"title":"Normal Supply Withdraw Allows Over-Withdrawal From Shared Liquidity","author":"gh0xt"},{"number":729,"title":"`supplyAmount_` Not Recalculated After Capping `withdrawAmountRaw_`, Allowing Full Protocol Drain","author":"Icon_0x"},{"number":764,"title":"Liquidity Drain via Uncapped Withdraw Amount in _processNormalSupplyAction","author":"Bizarro"},{"number":775,"title":"Inflated supply amount can be passed to liquidity for withdraw even when when withdrawamountraw is capped in function processnormalsupplyaction","author":"slowpoke"},{"number":794,"title":"`MoneyMarket` Can be Fully Drained by Anyone With Supply Position","author":"0xbzbee42"},{"number":834,"title":"Normal Withdraw Over-Withdraws Shared Liquidity Balance by Using Uncapped supplyAmount_ in External Transfer","author":"vivekd"},{"number":853,"title":"MM withdraw raw-cap desync allows pooled fund drain","author":"Merlinsan"},{"number":856,"title":"MoneyMarket `NORMAL_WITHDRAW` clamps only internal `withdrawAmountRaw_` but forwards the original (oversized) `supplyAmount_` to Liquidity, allowing an attacker to withdraw more tokens than their position and drain pooled Liquidity","author":"legat"},{"number":860,"title":"Normal supply withdraw caps storage debit but forwards the full requested amount to Liquidity, enabling withdrawal above balance and draining pooled MoneyMarket funds","author":"I1iveF0rTh1Sh1t"},{"number":865,"title":"Money Market over-withdraw: supplyAmount_ not recomputed after withdrawAmountRaw_ clamping drains Liquidity","author":"crab0saurus"},{"number":915,"title":"Attacker will drain pooled liquidity from honest suppliers","author":"neeloy"},{"number":918,"title":"Attacker will drain pooled liquidity from honest suppliers","author":"neeloy"},{"number":935,"title":"Withdrawal Exceeds Actual Balance Due to Missing supplyAmount_ Recalculation","author":"ElmInNyc99"},{"number":948,"title":"A malicious supplier will withdraw excess pooled liquidity from other suppliers","author":"Thisisit"},{"number":955,"title":"A liquidator will over-withdraw pooled liquidity during liquidation of normal supply","author":"Thisisit"},{"number":966,"title":"Attacker can withdraw more than supplied, draining pooled Liquidity from other suppliers","author":"AV"},{"number":970,"title":"Attacker can drain MoneyMarket's pooled liquidity funds","author":"0xShoonya"},{"number":992,"title":"Normal-Supply Withdraw Uses Uncapped supplyAmount for Liquidity Call and Can Drain Pooled Collateral","author":"rajatbeladiya"},{"number":1018,"title":"Incorrect Amount Used in Withdrawal Transfer Causes Loss of User Funds","author":"Waydou"},{"number":1027,"title":"Attacker will steal shared liquidity funds from all supply providers via uncapped LIQUIDITY.operate call in normal supply withdrawal","author":"Leaningone"},{"number":1033,"title":"Suppliers in moneyMarket can withdraw more assets than expected.","author":"0x37"},{"number":1080,"title":"Malicious Position Owner Will Drain Token Liquidity from the Protocol","author":"fuzious"},{"number":1081,"title":"Wrong clamp logic in `_processNormalSupplyAction` allows user to withdraw more than they supplied","author":"Riceee"},{"number":1096,"title":"MoneyMarket: Over-withdraw in normal supply withdraw drains pooled liquidity","author":"Edoscoba"},{"number":1126,"title":"Normal supply withdrawals clamp burned shares but still withdraw the full underlying amount, enabling pooled-liquidity drain","author":"xiaoming90"},{"number":1133,"title":"Unclamped Normal Withdraw Amount Drains Other Users' Deposits","author":"oct0pwn"},{"number":1197,"title":"User can drain funds from Money Market due to inconsistent withdraw capping","author":"Proof-of-Spirit"},{"number":1227,"title":"MoneyMarket normal-supply withdraw clamps only the raw burn, but withdraws the user-requested token amount from Liquidity -> attacker drains pooled funds","author":"thimthor"},{"number":1278,"title":"Partial withdraw caps raw accounting but withdraws uncapped amount from Liquidity, enabling cross-user drain","author":"Blackdruid"},{"number":1279,"title":"Drain Liquidity Pool via Uncapped Normal Withdrawal in MoneyMarket","author":"hirusha"},{"number":1281,"title":"Unrestricted arbitrary withdrawal amount in normal positions allows users to drain protocol funds","author":"crunter"},{"number":1307,"title":"An attacker can steal the pooled liquidity of other suppliers","author":"axelot"},{"number":1313,"title":"Excessive Withdrawal From Money Funds After Creating a Position","author":"nonso72"},{"number":1316,"title":"Normal withdraw path allows stealing other users\u2019 collateral","author":"ff4de"},{"number":1354,"title":"Withdrawal Beyond Deposit in _processNormalSupplyAction","author":"Frontrunner"},{"number":1358,"title":"Liquidation caps withdrawAmountRaw but calls LIQUIDITY.operate with the original uncapped withdrawAmount, allowing pooled-liquidity overdraw","author":"0xastronatey"}]},{"severity":"Medium","reward":160.51157220380543,"issues":[{"number":79,"title":"Stored-credit IOU is assigned to `to_` but only claimable by `msg.sender`, permanently locking funds on Liquidity failure","author":"0xastronatey"},{"number":234,"title":"Settle liquidity-fallback inflates stored balance and can credit wrong recipient","author":"uba"},{"number":350,"title":"Liquidity-layer revert will lock stored credits for EOA recipients","author":"Draxen"},{"number":356,"title":"DexV2 `settle()` LL-failure fallback credits \u201cwithdraw later\u201d storage to `to_` (recipient), but stored balances are only withdrawable by the callback contract (`msg.sender`) \u2192 permanent fund lock for EOAs","author":"legat"},{"number":584,"title":"Settlement fallback can permanently lock owed tokens when recipient is an EOA","author":"fullcounterhunter"},{"number":591,"title":"`settle()` fallback will permanently lock funds for MoneyMarket users because it credits `to_` but recovery debits only `msg.sender`","author":"jongwon"},{"number":618,"title":"Stored Credit Is recorded/credited on Liquidity Revert, Causing Unredeemable Funds and Withdrawal Liveness Failure","author":"nitinaimshigh"},{"number":664,"title":"DexV2 will permanently lock owed tokens for EOA recipients","author":"botdidy"},{"number":674,"title":"Liquidity-layer failure fallback during D4 borrow permanently locks funds in DEX","author":"lodelux"},{"number":675,"title":"DexV2 settle fallback will lock funds for to_ (EOA) recipients","author":"4Nescient"},{"number":678,"title":"liquidator will lose access to seized collateral as an arbitrary `to` address will receive non-withdrawable `stored` balances","author":"ZeroTrust"},{"number":711,"title":"D4 borrow fallback can lead to unclaimable borrow positions","author":"gh0xt"},{"number":754,"title":"FluidDexV2: Liquidity-failure fallback credits to_ but redemption is msg.sender-keyed, permanently locking user funds","author":"edantes"},{"number":760,"title":"Permanent Fund Lock in `_userStoredTokenAmount` for EOA Recipients","author":"Bizarro"},{"number":790,"title":"Stored tokens permanently locked for EOAs \u2014 recovery mechanism requires callback interface that EOAs cannot implement","author":"Jiberish"},{"number":808,"title":"Money Market Cannot Recover DEX Stored Balances from Settle Fallback","author":"gabkov"},{"number":843,"title":"Liquidity-layer fallback will lock payouts for MoneyMarket users","author":"neeloy"},{"number":857,"title":"User cannot withdraw stored token balance from DexV2 contract which is stored due to insufficient liquidity","author":"SarveshLimaye"},{"number":866,"title":"Liquidity fallback will permanently lock EOA withdrawals","author":"LeoGold"},{"number":957,"title":"EOA users will permanently lose funds stored in `_userStoredTokenAmount` mapping when `_callLiquidityLayer` fails","author":"yaioxy"},{"number":964,"title":"Liquidity Layer Fallback Writes IOU to User's EOA Address but Claim Path Reads from `msg.sender`, Permanently Locking Tokens","author":"Pelz"},{"number":976,"title":"Liquidity failure will permanently lock credited payouts when to_ is an EOA (unredeemable _userStoredTokenAmount)","author":"AV"},{"number":1001,"title":"DexV2 fallback credit is written to `to_` but consumable only by msg.sender, stranding funds when `to_ != msg.sender`","author":"rajatbeladiya"},{"number":1045,"title":"Stored token credits become unclaimable when Liquidity fallback is triggered","author":"natachi"},{"number":1047,"title":"Stored Token Fallback Lacks Withdrawal Path for EOA Recipients","author":"Kenn.eth"},{"number":1068,"title":"settle Fallback Path Can Permanently Lock User Funds Due to Callback-Based Withdrawal Requirement","author":"ExtraCaterpillar"},{"number":1076,"title":"DexV2 will permanently lock owed token payouts for EOA recipients when the Liquidity layer reverts","author":"Diavolo"},{"number":1093,"title":"EOA Users' Funds Permanently Stuck in _userStoredTokenAmount","author":"Waydou"},{"number":1098,"title":"An attacker will permanently lock net-out proceeds for D3/D4 users","author":"fuzious"},{"number":1111,"title":"Liquidity-layer failure fallback stores owed payouts under `to_`, making withdrawals/borrows/fees permanently unclaimable for EOAs","author":"xiaoming90"},{"number":1121,"title":"Zero `to_` in MoneyMarket\u2192DexV2 settlement misroutes withdrawals/borrows/fees to the MoneyMarket contract and can DoS native payouts","author":"xiaoming90"},{"number":1132,"title":"Liquidity Layer failure will permanently lock stored token amounts for recipients when `to_ != msg.sender`","author":"jo13"},{"number":1138,"title":"Liquidity Layer failure will permanently lock stored token amounts for EOA recipients","author":"jo13"},{"number":1177,"title":"During settle(), the Saved `_userStoredTokenAmount` Cannot Be Claimed","author":"Harry-Elite"},{"number":1214,"title":"LiquidityLayer failure credits stored balance under `to_`, but stored balances are spendable only by `msg.sender` (callback caller) -> EOA recipients payout becomes unclaimable","author":"thimthor"},{"number":1239,"title":"stored Tokens Are Permanently Locked for Addresses Without `IDexV2Callbacks` (EOAs, Smart Wallets)","author":"Emmanuel"},{"number":1243,"title":"Any user will permanently lock funds on Liquidity failure","author":"Proof-of-Spirit"},{"number":1291,"title":"settle() fallback will cause stuck stored-balance credits for users when Liquidity Layer reverts on withdrawal","author":"Leaningone"}]},{"severity":"Medium","reward":2516.2410821082603,"issues":[{"number":389,"title":"D3 Liquidation Penalty Manipulation via Pool Price","author":"yonko"},{"number":429,"title":"`MoneyMarket#liquidate()` D3 liquidation bonus can be increased via spot price manipulation","author":"Silvermist"},{"number":460,"title":"Liquidator can extract excess collateral by spot-steering D3 liquidation composition (oracle/spot basis drift)","author":"Baazigar"},{"number":580,"title":"Pool-price-based D3 liquidation penalty weighting enables MEV-extractable value beyond oracle-assessed risk","author":"Kalyan__tr"},{"number":669,"title":"D3 liquidation penalty weighting uses manipulable DEX pool price, enabling excess collateral seizure","author":"Slayer"},{"number":748,"title":"Average liquidation penalty for D3 Positions is Manipulable via AMM Price","author":"Laksmana"},{"number":757,"title":"D3 Liquidation Can Increase Profits by Manipulating DEX Spot Price to Shift Collateral Composition (Average Penalty Can Be \"Pushed Up\")","author":"ZeroTrust"},{"number":870,"title":"D4 liquidation paybackValue can be inflated or deflated by manipulating the DEX pool spot price, because HF check values debt using oracle-derived sqrtPriceX96 but the actual liquidation execution uses the DEX pool's sqrtPriceX96","author":"6PottedL"},{"number":980,"title":"MEV sandwich can increase D3 liquidation bonus when token liquidation penalties differ","author":"AV"},{"number":990,"title":"AT_POOL_PRICE in D3 liquidation path enables penalty weighting manipulation, causing extra collateral loss for position holders","author":"hexnikk"},{"number":1004,"title":"Liquidation uses pool spot price while health factor uses oracle price, leading to inconsistent and exploitable liquidation pricing","author":"Rizalfahmi"},{"number":1114,"title":"Liquidation uses DexV2 spot price to derive D3 collateral composition and weighted penalties, enabling MEV over-seizure","author":"xiaoming90"},{"number":1144,"title":"Pool Price Manipulation Inflates Average Liquidation Penalty in D3 Positions","author":"pashap9990"},{"number":1167,"title":"Pool Price Manipulation in D3 Liquidation Leading to Incorrect averageLiquidationPenalty_","author":"Bizarro"},{"number":1244,"title":"D3 liquidation uses manipulable DexV2 spot price to weight liquidation penalty, letting liquidators seize extra collateral","author":"thimthor"},{"number":1268,"title":"Pool Price Manipulation Inflates D3 Liquidation Penalty, Allowing Excess Collateral Seizure","author":"velev"},{"number":1390,"title":"Liquidators can manipulate the pool's price to gain more profit","author":"0x37"}]},{"severity":"Medium","reward":11041.258686718664,"issues":[{"number":348,"title":"Full liquidation always reverts due to hfLimit check on zero debt","author":"p1ramide"},{"number":432,"title":"`MoneyMarket#liquidate()` reverts when fully repaying debt because health factor infinity exceeds `hfLimit check","author":"Silvermist"},{"number":730,"title":"Missing debtValue != 0 guard in post-liquidation HF check causes full liquidation of single-debt NFTs to always revert","author":"maigadoh"},{"number":814,"title":"Full debts payback for normal borrow position reverts during liquidation","author":"iamephraim"},{"number":1183,"title":"Liquidation reverts when repaying the final remaining debt due to HF being set to type(uint256).max and compared against hfLimitForLiquidation","author":"xiaoming90"},{"number":1196,"title":"Liquidators will block full liquidation for MoneyMarket borrowers","author":"fuzious"},{"number":1319,"title":"Positions Near Liquidation Threshold Positions can Become Permanently Unliquidatable Due to hfLimit Check","author":"Audinarey"},{"number":1360,"title":"Full Debt Payback During Liquidation Reverts Due to HF Limit Check Not Handling Zero Debt","author":"Pelz"},{"number":1362,"title":"Full debt repayment during liquidation always reverts because hfLimit check does not exempt zero\u2011debt state","author":"LeoGold"}]},{"severity":"Invalid","reward":null,"issues":[{"number":1,"title":"Lack of maximum cap on dynamic fee override allows Controller to charge excessive swap fees (up to 65%)","author":"Aziz0033"},{"number":3,"title":"'Auth' role enables full protocol takeover via instant Oracle update, bypassing Governance hierarchy","author":"Aziz0033"},{"number":4,"title":"Unbounded Tick Traversal in Swap Loops Allows Gas-Based Denial of Service on Fluid DEX Pools","author":"Arif9212"},{"number":5,"title":"Silent Overflow in BigMath fromBigNumber Corrupts Financial Calculations","author":"OxRai"},{"number":9,"title":"Incorrect Tick Sign Encoding Causes Inverted D3/D4 Position Cap Ranges","author":"Arif9212"},{"number":10,"title":"Swaps will permanently lock user funds as reserve tracking diverges from concentrated liquidity position values","author":"Yifan"},{"number":12,"title":"Aggressive fee rounding will cause ~18% fee overcharge for swappers as protocol charges more than the nominal fee rate","author":"Yifan"},{"number":14,"title":"Health Factor validation relies on unsynchronized price sources, enabling under-collateralized D4 positions during normal market movement","author":"AnantaDeva"},{"number":15,"title":"Inconsistent unchecked usage in fee growth subtraction during tick crossing may cause unexpected reverts","author":"taronsung"},{"number":18,"title":"Persistent Liquidation Deadlock for Undercollateralized Positions Due to Minimum Payback Thresholds","author":"YF"},{"number":19,"title":"Zero-Cost Borrowing: settle() function bypasses Liquidity Layer accounting via Fast Path","author":"wilson2333"},{"number":22,"title":"PegOracle Hardcoded 1:1 Fallback Trap for ERC-20 Stablecoins","author":"eat-the-sky"},{"number":24,"title":"Users will be permanently unable to create wallets due to the deploy function call reversal","author":"0x1adz1"},{"number":25,"title":"MoneyMarket fee collection skips Health Factor validation enabling borrow limit bypass via D3/D4 fee accrual","author":"attacker_code"},{"number":30,"title":"Protocol will suffer insolvency due to aggressive sqrtPriceX96 compression (20 bits) violating documentation (64 bits)","author":"unicuervo"},{"number":31,"title":"Liquidity Providers suffer yield loss due to incorrect BIG_COEFFICIENT_SIZE (32 bits) violating documentation (74 bits)","author":"unicuervo"},{"number":32,"title":"Incorrect order of scaling operations in `_useFeeStoredForLiquidation` causes precision loss","author":"Erpal"},{"number":33,"title":"Accounting update skipped when liquidity layer fails with negative net amount","author":"Erpal"},{"number":34,"title":"Traders will steal 100% of swap fees in D4 pools * Traders will steal 100% of swap fees from Liquidity Providers and the Protocol","author":"EZeek33"},{"number":35,"title":"Fee-on-Transfer tokens will cause total pool insolvency and loss of funds for Liquidity Providers","author":"EZeek33"},{"number":37,"title":"UUPS upgrade accepts an ERC1967Proxy as the new implementation and can permanently brick the proxy","author":"I1iveF0rTh1Sh1t"},{"number":39,"title":"Liquidation Reverts When Branch Debt Falls Below 100 Wei, Creating Unliquidatable \"Zombie\" Positions","author":"AbSattar"},{"number":41,"title":"Gas-limited external call desynchronizes DEX accounting from Liquidity Layer, causing Ghost States and Protocol Insolvency","author":"EZeek33"},{"number":44,"title":"Lack of reentrancy locks in adminModule.sol allows privileged interference with active user operations and transient storage corruption","author":"EZeek33"},{"number":48,"title":"D3/D4 Position Slot Leak in Money Market","author":"JuggerNaut"},{"number":49,"title":"Missing Deadline Protection in All DEX V2 User Operations Enables Forced Execution at Worst-Case Slippage","author":"Mr.BlackKeys"},{"number":58,"title":"_userStoredTokenAmount credits bypass LIQUIDITY debt tracking, enabling interest-free borrowing","author":"AnantaDeva"},{"number":60,"title":"Minimum amount validation prevents repayment of dust debt, permanently locking user collateral","author":"Slayer"},{"number":61,"title":"Fee dependency may block liquidation","author":"Mhayat"},{"number":62,"title":"ETH payback mismanagement can block liquidation","author":"Mhayat"},{"number":63,"title":"Arithmetic Overflow in Debt Calculation Permanently Bricks Payback() & Liquidate() in High-Supply Token Pools","author":"Um158057"},{"number":65,"title":"Rounding / small collateral edge cases prevent tiny liquidations","author":"Mhayat"},{"number":66,"title":"Precision loss from double BigMath conversion will prevent users from executing swaps","author":"Hendobox"},{"number":67,"title":"Denial of Service in FluidVaultT1 liquidation via unbounded loop in _fetchNextTopTick","author":"lavrenuk"},{"number":68,"title":"Liquidators will permanently deadlock vault liquidation causing protocol insolvency risk for Fluid DEX V2","author":"AbSattar"},{"number":70,"title":"Atomic Deadlock in DEX V2: Liquidity Rounding Breaks DEX Control Flow","author":"Um158057"},{"number":71,"title":"Payback Function Safety Checks Disabled","author":"aiota"},{"number":72,"title":"Unchecked Arithmetic Requires Systematic Review","author":"aiota"},{"number":84,"title":"Critical Oracle Bypass: Static centerPrice in D2 Pools due to Disabled Update Logic","author":"Viridis"},{"number":85,"title":"Asymmetric rounding in Smart Debt (D4) liquidity calculation will prevent users from closing positions","author":"yaku"},{"number":86,"title":"BigMathMinified::fromBigNumber reads dirty bits, leading to substantial value inflation","author":"ed-waypoint"},{"number":88,"title":"Center Price Oracle Failure Causes Complete Pool DoS and Locks User Funds","author":"Mr.BlackKeys"},{"number":89,"title":"MoneyMarket Oracle Failure Causes Complete Protocol DoS and Blocks Liquidations Leading to Bad Debt","author":"Mr.BlackKeys"},{"number":90,"title":"Liquidation becomes uneconomic when position count is maxed","author":"bratwork"},{"number":91,"title":"`absorb` function corrupts `absorbedLiquidity` state due to unsafe packed addition causing debt overflow into collateral","author":"lavrenuk"},{"number":92,"title":"Attacker will cause DoS and potential fund loss for D4 pool LPs as int256 overflow occurs in reserve calculations","author":"Daian0s"},{"number":94,"title":"D4 pool users will suffer accounting errors as debt-to-reserve round-trip conversions lose precision","author":"Daian0s"},{"number":95,"title":"D4 pool LPs will lose access to funds as extreme prices cause reserve calculation to revert","author":"Daian0s"},{"number":96,"title":"D4 pool operations will revert for LPs as negative p1 squared can exceed p2 causing sqrt underflow","author":"Daian0s"},{"number":97,"title":"Users will lose D3/D4 payouts as `operate()` forwards `to = address(0)` and DexV2 defaults it to MoneyMarket","author":"Baazigar"},{"number":100,"title":"Inaccurate quadratic solving will cause valid position creations to revert for D4 users","author":"Ibukun"},{"number":102,"title":"Unsafe integer casting in Smart Debt Math will cause transaction reverts for D4 position owners","author":"Ibukun"},{"number":103,"title":"Inconsistent oracle price validation between `operate` and `liquidate` creates unfair denial of service for users","author":"lavrenuk"},{"number":104,"title":"Attacker will corrupt pending transfer accounting causing loss of funds for users","author":"sansekerta"},{"number":105,"title":"Division by zero in `calcRateV1` causes permanent DoS at 100% utilization if kink is set to 100%","author":"lavrenuk"},{"number":106,"title":"LP fee accounting will be corrupted causing loss of fees for liquidity providers","author":"sansekerta"},{"number":107,"title":"absorb() permanently desynchronizes tickHasDebt bitmap from tick data, causing unreachable ticks and liquidation deadlocks","author":"AbSattar"},{"number":109,"title":"Liquidator will steal liquidation penalty fees from the protocol by exploiting integer rounding on imbalanced D3 positions","author":"TradingViews"},{"number":111,"title":"Reentrancy via Malicious Token Callback in Permissionless D3 Pool Allows Draining Arbitrary Tokens from DEX Reserves","author":"Zeethefist"},{"number":113,"title":"Attacker will steal millions in collateral from NFT position holders due to operator precedence validation bypass","author":"TradingViews"},{"number":114,"title":"Debt Erasure via D4 Smart Debt Valuation Mismatch","author":"kkkkkkkkkk7"},{"number":115,"title":"Stale Chainlink Price","author":"kkkkkkkkkk7"},{"number":116,"title":"Oracle Storage Layout Mismatch in DexSmartT4CLOracle","author":"kkkkkkkkkk7"},{"number":117,"title":"BigMath Logic Flaw - Debt Erasure via Silent Underflow","author":"kkkkkkkkkk7"},{"number":119,"title":"Direct Seizure of User Principal (up to 1%) via Callback Surplus Accounting Desync","author":"Um158057"},{"number":120,"title":"Attackers will liquidate healthy users due to unguarded callback reentrancy in D3/D4 operations","author":"TradingViews"},{"number":121,"title":"Attackers will corrupt multi-position NFTs and drain users due to nested DEX callback reentrancy","author":"TradingViews"},{"number":123,"title":"absorb() orphans merged child branches, wiping user debt without recording it in absorbedLiquidity, leading to silent vault insolvency","author":"AbSattar"},{"number":124,"title":"Traders will lose 0.01%-0.1% on every swap due to double precision rounding in D3","author":"TradingViews"},{"number":125,"title":"Unauthorized Triggering of Automated Withdrawal Limits (\"Whale Trap\")","author":"Um158057"},{"number":126,"title":"Liquidation Denial of Service via Integer Overflow in Smart Debt Math","author":"hodlturk"},{"number":127,"title":"Hardcoded Mainnet Dependencies in Buyback Cause Permanent DoS on Supported L2 Chains","author":"Acson"},{"number":128,"title":"Protocol will lose $30-75M annually as D4 swapOut records incorrect pending transfer amounts","author":"TradingViews"},{"number":130,"title":"Protocol-Wide DoS via DEX Rebalance Freeze","author":"Um158057"},{"number":131,"title":"Overflow in D4 reserve math DoSes extreme borrow ranges","author":"vivekd"},{"number":132,"title":"Dust Debt Causes Division by Zero in _calculateDebtReserves, Permanently Freezing Pool","author":"Acson"},{"number":133,"title":"Zero-rate configuration will cause a temporary denial of service for the Rate Handler automation","author":"bosz"},{"number":137,"title":"Indefinite Fund Confiscation via Settle Fallback Logic","author":"gurgeled"},{"number":138,"title":"15-bit Timestamp Compression Causes Oracle Price Freeze for >9.1 Hour Inactivity","author":"ArkheionX"},{"number":139,"title":"BigMath roundUp Logic Causes MAX_UINT to Overflow to Zero, Allowing Debt Erasure","author":"ArkheionX"},{"number":140,"title":"Active Liquidity Overflow in Swap Logic Corrupts POOL_ACCOUNTING_FLAG","author":"ArkheionX"},{"number":141,"title":"DexV2PoolLock Library Fails to Prevent Read-Only Reentrancy, Exposing Integrators to Price Manipulation","author":"ArkheionX"},{"number":142,"title":"Shared Storage Slot for Pausable and ReentrancyGuard Causes Permanent Denial of Service when Protocol is Paused","author":"ArkheionX"},{"number":143,"title":"Protocol Fee Theft via D4 SwapIn Logic","author":"gurgeled"},{"number":144,"title":"Incorrect Bitwise Masking in _updateOracle Permanently Locks the Reentrancy Guard, Causing Protocol-Wide DoS","author":"ArkheionX"},{"number":145,"title":"Protocol Cut Fee Precision Loss Results in Revenue Loss","author":"Greedy_Biggie"},{"number":148,"title":"Oracle Price Manipulation possible due to unsafe price selection logic in `_swapIn`","author":"lavrenuk"},{"number":150,"title":"Price manipulation via spot-only pricing in D4 borrow/payback (missing TWAP/deviation)","author":"Faraone321"},{"number":151,"title":"Smart Debt Quadratic Math Overflow in D4 Pools","author":"TOSHI"},{"number":155,"title":"Missing Liquidation Logic in D3 'Smart Collateral' Module","author":"gurgeled"},{"number":161,"title":"Controller will silently disable dynamic fee MEV protection for liquidity providers by setting priceImpactToFeeDivisionFactor to zero","author":"luckyidiot"},{"number":163,"title":"Attacker will corrupt pool state and drain funds from liquidity providers","author":"voidworks"},{"number":164,"title":"Stale price usage in Oracle view methods allows borrowing against devalued collateral","author":"gurgeled"},{"number":165,"title":"Missing Chainlink Circuit Breaker Checks allow borrowing against insoluble assets and bypasses Oracle Fallback","author":"gurgeled"},{"number":166,"title":"User will steal funds from the protocol by exploiting `settle` fallback when Liquidity Layer interaction fails","author":"Orionn"},{"number":167,"title":"Unvalidated caller-supplied dex_ addresses will cause ETH loss and quote manipulation on-chain callers","author":"reentrantai"},{"number":168,"title":"Protocol will suffer revenue loss due to fee position debt growing faster than asset value in Smart Debt (D4) pools","author":"Orionn"},{"number":169,"title":"Borrow Cap Accounting Drift Causes Permanent Borrow Denial After Net-Zero Borrow/Payback Cycles","author":"FrostBurnXI"},{"number":171,"title":"User will be unable to complete settle() operations as the protocol leaves pending transfers uncleared","author":"AbSattar"},{"number":172,"title":"Strict Arithmetic in StETH Claims Permanently Locks User Funds","author":"gurgeled"},{"number":173,"title":"Silent Value Truncation in BigMath toBigNumber Causes Catastrophic Fund Loss","author":"ahmadkhan44"},{"number":175,"title":"Unchecked exponent increment in toBigNumber leads to exponent wrap-around and massive value corruption","author":"ahmadkhan44"},{"number":176,"title":"Attacker will steal protocol and LP funds through signed integer overflow in Smart Debt Math quadratic calculations","author":"ChefJay"},{"number":177,"title":"Attacker will extract value from LPs through cumulative precision loss in exchange price conversions","author":"ChefJay"},{"number":178,"title":"Missing Liquidator Address in Callback Prevents ERC20 Debt Liquidation","author":"Zeethefist"},{"number":179,"title":"Attacker will drain pool reserves through unchecked transient storage manipulation in multi-call scenarios","author":"ChefJay"},{"number":181,"title":"A panic (0x11) triggered during the liquidation process after `Absorb` in the Liquidity payback path, causing bad debts to be unable to be liquidated under extreme price conditions (DoS).","author":"8olidity"},{"number":182,"title":"Position Index Manipulation During Liquidation Allows Incorrect Collateral Seizure","author":"Zeethefist"},{"number":183,"title":"Fee-on-Transfer / Deflationary Tokens Cause Accounting Mismatch (Underpayment Credited as Full Amount)","author":"alaskanking"},{"number":184,"title":"Liquidation logic will skip token1 fee, causing liquidators to receive less collateral on small D4 positions","author":"kai-agi"},{"number":186,"title":"An attacker will cause double liquidation or state corruption for the protocol","author":"0xUnderflow"},{"number":187,"title":"An attacker will cause state corruption or fund extraction for the protocol","author":"0xUnderflow"},{"number":188,"title":"An attacker (or user) will cause data corruption or fund loss for users","author":"0xUnderflow"},{"number":189,"title":"The overflow will cause settlement revert for users (DoS)","author":"0xUnderflow"},{"number":190,"title":"An arbitrageur will cause value extraction for other depositors","author":"0xUnderflow"},{"number":191,"title":"The first depositor will cause value extraction for later depositors","author":"0xUnderflow"},{"number":192,"title":"The protocol will cause approximate loss for users","author":"0xUnderflow"},{"number":193,"title":"Edge-case positions will cause DoS for the affected user","author":"0xUnderflow"},{"number":194,"title":"BigMath rounding will cause approximate loss for users","author":"0xUnderflow"},{"number":196,"title":"n attacker will cause implementation initializable by anyone (protocol defense-in-depth)","author":"0xUnderflow"},{"number":198,"title":"Broken Core Accounting Invariant Leading to Irrecoverable LP Fee Loss","author":"The_Last_Gladiator"},{"number":199,"title":"Liquidator will profit 530%+ from D4 oracle/pool sqrtPrice mismatch during liquidation","author":"coinsspor"},{"number":200,"title":"Vault exchange price overflow will permanently freeze vault operations for users.","author":"AbSattar"},{"number":201,"title":"Rounding mismatch between MoneyMarket and Liquidity raw-debt conversions leaves unpayable residual debt and permanently freezes collateral withdrawals","author":"0xastronatey"},{"number":202,"title":"Missing refund of Excess ETH in `fTokenNativeUnderlying::mintNative`","author":"0xfallin1"},{"number":205,"title":"State-Dependent Fee Desynchronization via Controller-Supplied Dynamic Fee Override in Swap Loops","author":"attacker_code"},{"number":206,"title":"Cannot list standard tokens that do not implement `decimals()`","author":"Tigerfrake"},{"number":208,"title":"DENIAL-OF-SERVICE VIA SUPPLYEXCHANGEPRICE OVERFLOW IN SWAPMODULE","author":"neme"},{"number":210,"title":"Vault liquidation math can silently zero user debt, causing vault insolvency for lenders","author":"AbSattar"},{"number":212,"title":"DEX\u2013Liquidity state divergence when settle fallback runs (net inflow)","author":"uba"},{"number":213,"title":"Time Delta overflow in TWAP Oracle causes incorrect pricing for pools inactive > 48 days","author":"LogicMind_0x"},{"number":214,"title":"Unauthorized use of 'absorb' in liquidation allows users to drain protocol reserves","author":"LogicMind_0x"},{"number":215,"title":"Borrower will underpay D4 debt, harming the protocol","author":"VolodymyrStetsenko"},{"number":216,"title":"Multi-Source State Inconsistency in _getLimitsAndAvailability","author":"RoushanGoswami"},{"number":217,"title":"Smart Collateral withdrawable NOT balance-capped","author":"RoushanGoswami"},{"number":218,"title":"Global `_msgSender` State Used as Both Sender Forwarder and Reentrancy Lock Causes Deterministic DoS of Legitimate Protocol Flows","author":"attacker_code"},{"number":219,"title":"Storage Truncation in updateHfLimitForLiquidation()","author":"0x4non"},{"number":220,"title":"Fully Vested Users Are Re-Locked Upon Partial Withdrawal Due to Flawed Limit Calculation","author":"lavrenuk"},{"number":223,"title":"Future Upgrades will Corrupt Storage for Fluid DexV2 Protocol","author":"eat-the-sky"},{"number":224,"title":"Critical Read-only Reentrancy in _swapOut allows draining Money Market due to CEI Violation","author":"AkobirSec"},{"number":225,"title":"Pause can be bypass via existing positions","author":"0x4non"},{"number":226,"title":"Inconsistent Tick Precision between Compressed Storage and Oracle leads to Wrongful Liquidation","author":"StevenJ"},{"number":228,"title":"An attacker will cause pool-wide insolvency and fee dilution for Liquidity Providers by inflating `activeLiquidity` via rounding manipulation in D4 User Module.","author":"Aziz0033"},{"number":230,"title":"Insufficiently tracked Permissioned Dexes undermine protocol upgrade","author":"Tigerfrake"},{"number":231,"title":"Permanent Liquidation DoS via 'Ghost Tick' logic error (Vault__TickIsEmpty) causes guaranteed bad debt","author":"StevenJ"},{"number":235,"title":"borrow backs of underlying tokens in D3 Smart Collateral Positions can be used to steal fees from honest LP providers.","author":"adeolu"},{"number":236,"title":"An attacker (or a reverted Liquidity operation) will permanently freeze the stored token balance of an EOA user.","author":"flora2627"},{"number":237,"title":"`rebalance` treats user-stored tokens as protocol-owned and can send them to Liquidity, leading to loss of user funds and protocol insolvency","author":"uba"},{"number":238,"title":"Missing Upper Bound After Scaling","author":"neme"},{"number":240,"title":"Debt Repayment Instantly Slashes User's Borrowing Limit, Punishing Healthy Protocol Usage","author":"lavrenuk"},{"number":241,"title":"Early Liquidation via Round-Up in Health Factor Limit","author":"EtherEngineer"},{"number":242,"title":"Zero-liquidity transitions reset sqrtPriceStartX96, bypassing cumulative price-movement limits in DEX V2 swaps","author":"AbSattar"},{"number":243,"title":"Protocol will suffer silent data corruption and incorrect calculations when using large BigNumber values","author":"felconsec"},{"number":244,"title":"Rounding Error in Liquidation Logic Allows Insolvent Users to Retain Collateral","author":"lavrenuk"},{"number":245,"title":"M-1: D3 Liquidation Price Discrepancy \u2014 Pool Price vs Oracle Price for Token Split","author":"idriss"},{"number":246,"title":"M-2: D3 Fee Collection Skipped During Liquidation \u2014 HF/Liquidation Collateral Asymmetry","author":"idriss"},{"number":248,"title":"Attacker will corrupt protocol accounting by faking token receipt via malicious callback, affecting the protocol and users","author":"felconsec"},{"number":249,"title":"Permanent Pool Corruption via BigMath Coefficient Overflow","author":"ahmadkhan44"},{"number":250,"title":"Global Fee Growth Accumulation Precision Loss","author":"Uhudsavasindankacanokcu2"},{"number":251,"title":"Composite Rounding Errors in Smart Debt (D4) Swap Logic","author":"Uhudsavasindankacanokcu2"},{"number":252,"title":"tate-Changing Reentrancy via dexCallback","author":"ahmadkhan44"},{"number":253,"title":"Attacker will bypass dynamic fee persistence by resetting price impact to zero, causing loss of fee revenue for Liquidity Providers","author":"AbSattar"},{"number":254,"title":"Incomplete Position Index Adjustment Causes Type Confusion and Seizes Wrong Position's Collateral.","author":"codecoffeeguy"},{"number":256,"title":"LPs will lose fees through BigMath precision loss in global fee growth accumulation","author":"ChefJay"},{"number":257,"title":"`_totalSupply == 0` will set `rewardPerTokenStored` to 0, causing DoS in reward collection and accounting pollution.","author":"8olidity"},{"number":258,"title":"Attacker will manipulate pool price through BigMath rounding exploitation in sqrt price storage","author":"ChefJay"},{"number":259,"title":"VaultT1: Transferable NFT Positions + Payback Not Bound to Expected Owner, Leading to \"Incorrect Repayment to a New Owner\"","author":"8olidity"},{"number":264,"title":"Incorrect `operate()` documentation for `positionIndex_` causes callers / integrators transactions to always revert","author":"BoyD"},{"number":265,"title":"Precision Loss in D4 Smart Debt Round-Trip Calculation Leads to Protocol Fund Loss","author":"qwe638853"},{"number":267,"title":"Attacker will drain Fluid DEX liquidity by exploiting inverted settlement logic during failed Liquidity Layer calls","author":"kimchiwarrior"},{"number":268,"title":"Critical Read-only Reentrancy in deposit allows inflating share price due to CEI Violation","author":"AkobirSec"},{"number":271,"title":"Oracle Price Collapse via Precision Loss When Asset Price < 1.0","author":"Aex"},{"number":272,"title":"Forced native ETH refund in `_handleMsgDetails` can revert `operate/liquidate/changeEmode` causing DoS for non-payable contract callers / integrators","author":"BoyD"},{"number":273,"title":"Borrowers can reduce smart debt below borrowed amount due to non-invertible quadratic debt math","author":"alphaizen"},{"number":274,"title":"Missing deadline on swaps allow sandwich attacks and JIT liquidity","author":"0x4non"},{"number":275,"title":"Liquidation of positions that became insolvent through interest accrual fails with arithmetic underflow","author":"VolodymyrStetsenko"},{"number":277,"title":"D4 swaps are permissionless despite documentation stating D4 pools remain permissioned","author":"0xb0k0"},{"number":278,"title":"Fee-on-transfer tokens can drain shared balances across pools","author":"0xb0k0"},{"number":279,"title":"Pool creation and trading share the same whitelist, allowing whitelisted traders to list unauthorized pools","author":"0xb0k0"},{"number":280,"title":"`storeAmount` can mint unbacked stored balances, allowing drain of shared reserves","author":"0xb0k0"},{"number":281,"title":"D4 Payback recomputes reserve requirements under price discontinuity without reconciliation, allowing unbacked debt clearance","author":"AbSattar"},{"number":284,"title":"Systemic scaling underflow triggers Panic(0x11) pre-guard, breaking perfect position finality for 18-dec tokens","author":"sftwr"},{"number":286,"title":"jdhart81 - Fee Growth Underflow in Unchecked Block Due to BigMath Precision Loss","author":"Viridis"},{"number":288,"title":"Inconsistent price sources will cause bad debt accumulation for the protocol","author":"Orionn"},{"number":290,"title":"LPs will drain pool principal reserves causing insolvency for other LPs","author":"kimchiwarrior"},{"number":291,"title":"Critical Logic Flaw in addOrRemoveTokens Allows Withdrawal Amplification via msg.value, Leading to Irrecoverable Losses","author":"watsonclyde"},{"number":292,"title":"User will escape liquidation and cause bad debt for the protocol by switching E-Mode","author":"VolodymyrStetsenko"},{"number":293,"title":"A caller will lose attached native ETH when `settle()` requires **0** native ETH but still accepts `msg.value`","author":"Baazigar"},{"number":295,"title":"\ud83d\udd34 Critical: Deposit Amount Double Underflow in colOperations.sol - Direct Fund Loss","author":"Viridis"},{"number":296,"title":"\ud83d\udd34 High: Range Shift Completion Boundary Off-by-One in _calcRangeShifting() - State Inconsistency","author":"Viridis"},{"number":297,"title":"Total Loss of Deposit via Share Truncation in VaultT2 mainOperate","author":"Aex"},{"number":298,"title":"Malicious User will cause Protocol Insolvency and Permanent DoS for Liquidity Providers","author":"kimchiwarrior"},{"number":299,"title":"Attacker will drain Fluid DEX liquidity by creating ghost credits via reentrancy","author":"kimchiwarrior"},{"number":300,"title":"Chainlink Oracle Staleness Not Checked","author":"alaskanking"},{"number":301,"title":"Attacker will bypass Oracle Rate Caps of FluidCappedRate","author":"joker158"},{"number":313,"title":"Health Factor Corruption and Uncollateralized Debt due to Precision Loss in `_calculateSqrtPriceX96`","author":"EFCCWEB3"},{"number":315,"title":"Potential Storage Collision in Delegatecall Pattern","author":"0x_Taigong"},{"number":321,"title":"Smart Vaults Interest Accrual Depends on Update Frequency, Leading to Yield Leakage","author":"lavrenuk"},{"number":322,"title":"Oracle Price Collapse for Large Asset Amounts in D1 Pools via Precision Loss","author":"Aex"},{"number":323,"title":"Chainlink Oracle Data is Not Validated for Staleness or Integrity","author":"lavrenuk"},{"number":324,"title":"Attacker will drain Fluid DexV2 Protocol reserves via arithmetic inversion in settle function's convenience logic","author":"kimchiwarrior"},{"number":325,"title":"Arithmetic Overflow in D4 Smart Debt Reserve Calculation Freezes Liquidations and Closed-Loop Positions","author":"EFCCWEB3"},{"number":328,"title":"Position Index Misalignment via \"Swap-and-Pop\" Deletion in Atomic Multi-Step Operations","author":"EFCCWEB3"},{"number":329,"title":"Dynamic Fee Manipulation via Forced Decay Reset on Price Impact Sign Inversion","author":"EFCCWEB3"},{"number":330,"title":"Missing Slippage Protection in FluidDexV2 Liquidation Enables impacts from Frontrunning, Unintended Collateral Seizure, and Liquidator Loss","author":"Bigsam"},{"number":332,"title":"Malicious callback callee will force transaction revert for startOperation() integrators","author":"dexters"},{"number":333,"title":"Gas Limit Denial of Service via NFT Position Packing in Isolated Collateral Liquidations","author":"EFCCWEB3"},{"number":334,"title":"Attacker will permanently brick all protocol operations for all users through counter underflow in pendingTransfers library","author":"dexters"},{"number":336,"title":"Cross-Function Reentrancy via LIQUIDITY.operate() Callback Enables Share Inflation Attack","author":"Viridis"},{"number":337,"title":"Precision Loss in Adjusted Token Amount Calculations Causes Cumulative Reserve Underflow","author":"Viridis"},{"number":338,"title":"State Change After External Call in _arbitrage Enables Oracle Price Manipulation","author":"Viridis"},{"number":339,"title":"Denial of Service and Fund Lock in ETH Transfers via Unsafe Casting of netAmount_","author":"Aex"},{"number":340,"title":"Asymmetric Oracle Capping creates unliquidatable 'Zombie Positions' during market crashes, guaranteeing Protocol Insolvency","author":"StevenJ"},{"number":341,"title":"DoS in DEX Rebalance due to BigMath \"Precision Gap\" causing hard revert, permanently blocking Revenue Collection","author":"StevenJ"},{"number":342,"title":"Wrong conditional check breaks `updateFeeVersion0`","author":"0xCrypt0nite"},{"number":343,"title":"Empty revert(0,0) in reentrancy lock will cause integration failures and gas waste for external integrators","author":"dexters"},{"number":344,"title":"Malicious auth will drain seeded liquidity from other auths","author":"dexters"},{"number":345,"title":"[H-01] DoS vulnerability in settle() through liquidity layer failure handling","author":"Yahaya-Salisu"},{"number":346,"title":"Any user will steal all withdrawal funds from any other user by manipulating the to_ parameter in settle()","author":"dexters"},{"number":349,"title":"[H-1] Same-block deposit and withdrawal enables JIT liquidity attacks causing unfair fee extraction from honest LPs","author":"frustramatic"},{"number":351,"title":"Users will receive unfavorable execution as transactions can execute at stale prices","author":"Heavy-Check"},{"number":352,"title":"Quadratic Equation Precision Loss in Debt-Reserve Conversions Causes Direct Loss of User Funds in Borrow/Payback Operations","author":"ElijahO"},{"number":353,"title":"L2 Sequencer Grace Period Logic is Flawed, Allowing Exploits After Short Outages","author":"lavrenuk"},{"number":355,"title":"Smart Debt Math Precision Loss Enables 0.16% Fund Extraction via Asymmetric Borrowing","author":"kkon82"},{"number":357,"title":"Fee Growth Underflow via BigMath Precision Loss Enables Fee Theft","author":"kkon82"},{"number":359,"title":"Attacker will over-borrow against inflated D3/D4 collateral value causing protocol bad debt","author":"Bozwkd"},{"number":360,"title":"Liquidator will seize incorrect collateral amounts causing bad debt or unfair liquidations affecting protocol and users","author":"Bozwkd"},{"number":361,"title":"Attacker could inflate `_unaccountedBorrowAmount` by repeatedly `donate -> borrow` causing permanent DoS for rebalance() and bypass the `debtCeiling` limit","author":"Orionn"},{"number":362,"title":"Malicious contract will bypass authorization and execute unauthorized liquidations against Fluid protocol users","author":"watsonclyde"},{"number":363,"title":"Permanent Denial of Service in D4 Pools due to intermediate math overflow (p1 * p1) in Smart Debt Logic","author":"StevenJ"},{"number":364,"title":"FluidDexV2#settle() `storeAmount` credits stored balance without inbound tokens causing drain of funds","author":"Silvermist"},{"number":368,"title":"[H-2] Unchecked delegatecall to arbitrary implementation addresses in operateAdmin","author":"Yahaya-Salisu"},{"number":369,"title":"Native token (ETH) permanently lost when liquidity layer fails during `settle()` with `netAmount_ > 0`","author":"Kalyan__tr"},{"number":370,"title":"Arithmetic underflow in Liquidity payback causes \u201crepay all\u201d to revert for valid debt positions","author":"heavyw8t"},{"number":371,"title":"`updateTokenSupplyCap()` and `updateTokenDebtCap()` store cap in raw units causing token-denominated caps to drift over time","author":"Silvermist"},{"number":372,"title":"Critical Read-Only Reentrancy in `FluidDexT1` oracle updates allows price manipulation","author":"lavrenuk"},{"number":376,"title":"Users can receive lower tokens than expected at the time of withdrawal due to missing slippage protection","author":"EddiePumpin"},{"number":377,"title":"Stale setApprovalForAll Persists After Final NFT Transfer","author":"EddiePumpin"},{"number":378,"title":"Wide range of price check allows for stale price","author":"EddiePumpin"},{"number":379,"title":"Precision Loss in BigMath Round-Trip Conversions Causes Token Amount Discrepancies","author":"Viridis"},{"number":380,"title":"Division Before Multiplication in dexCalcs Causes Precision Loss in Withdrawal Limits","author":"Viridis"},{"number":381,"title":"Callback Reentrancy Vector in dexCallback May Allow State Manipulation","author":"Viridis"},{"number":382,"title":"int128 Sentinel Values May Cause Unexpected Behavior in Edge Cases","author":"Viridis"},{"number":383,"title":"Attacker will manipulate oracle price via consecutive cross-block swaps bypassing 5% limit","author":"moneyhao"},{"number":384,"title":"User operations will be blocked when collateral and debt pool prices are equal causing DoS","author":"moneyhao"},{"number":388,"title":"Health Factor Not Validated Before Debt Payback","author":"ViquetourOnTop"},{"number":391,"title":"[M-01] Missing Slippage Protection in Liquidity Operations","author":"Yahaya-Salisu"},{"number":392,"title":"Malicious token will execute zero-fee swaps, depriving LPs of protocol revenue","author":"0xSpider_Raphl"},{"number":393,"title":"[M-02] Precision Loss in Token Amount Conversions","author":"Yahaya-Salisu"},{"number":397,"title":"Logic Inversion in D4 Smart Debt Pools allows Attackers to Drain Funds via Incorrect Reserve Updates","author":"MRSHEEP"},{"number":400,"title":"Borrow Limit Bypass Vulnerability in Money Market","author":"ViquetourOnTop"},{"number":401,"title":"D3 Liquidation Rounding Forces Liquidators to Receive 1 Wei Collateral While Paying Full Debt Value Causing Economic Loss and Bad Debt Accumulation","author":"ElijahO"},{"number":402,"title":"Users lose tokens when deposit fails because DexV2 takes the money but forgets to record it","author":"Victor_TheOracle"},{"number":404,"title":"Using tick-derived geometric mean without validating current pool price leads to slippage-based mispricing allowing unfair/incorrect debt creation","author":"makeWeb3safe"},{"number":405,"title":"Unconditional `coefficient += 1` in `BigMathMinified.toBigNumber()` inflates exact values when `roundUp = true`","author":"ranzo"},{"number":408,"title":"Oracle Staleness Validation Missing Allows Use of Stale Prices","author":"deucefury"},{"number":409,"title":"Extensive Unchecked Arithmetic Blocks Without Documented Safety Invariants","author":"deucefury"},{"number":410,"title":"Negative Oracle Price Cast to uint256 Causes Massive Price Inflation","author":"deucefury"},{"number":411,"title":"Liquidation Division Order Bug Returns Zero Collateral for Partial Liquidations","author":"deucefury"},{"number":413,"title":"Critical Read-only Reentrancy in borrow allows creating unbacked debt due to CEI Violation","author":"AkobirSec"},{"number":414,"title":"Borrower will increase D4 liquidation payback via low-liquidity spot manipulation","author":"vangrim"},{"number":416,"title":"Uncleared `_positionFeeStored` prevents D3 position deletion, causing permanent loss of user fees and systemic capacity leakage.","author":"Orionn"},{"number":418,"title":"Reserve Accounting Bug: Fee-Offset Deposits Incorrectly Increase Reserves by Full Amount","author":"frankauditcraft"},{"number":419,"title":"Liquidators will fail to liquidate D4 positions when using type(uint256).max for payback amounts","author":"BogdanCastraveti"},{"number":421,"title":"`MoneyMarket#_processNormalBorrowAction()` payback-all uses stale exchange price causing untracked debt","author":"Silvermist"},{"number":422,"title":"`MoneyMarket#liquidate()` uses stale exchange price causing over-credited debt repayment and protocol bad debt","author":"Silvermist"},{"number":424,"title":"BigMath RoundUp Overflow Handling Causes Double Precision Loss in Price and Fee Storage Leading to Systematic Fund Loss Exceeding 1%","author":"ElijahO"},{"number":425,"title":"Not enough Slippage Protection in Liquidation Execution","author":"HakeraGasy"},{"number":426,"title":"Conceptual Error in Determining Storage Slot Mapping in `DexV2BaseSlotsLink` Leads to Incorrect Storage Access","author":"JuggerNaut"},{"number":433,"title":"Total Collateral Value Can Become Lower Than Total Debt Value Due to Asymmetric Rounding Between Supply and Borrow Accounting","author":"ShadSF"},{"number":434,"title":"Attacker will cause protocol insolvency and drain funds as unsafe int256 to uint256 cast in _calculateReservesFromDebtAmounts underflows to max uint256","author":"dalitblue"},{"number":435,"title":"Arithmetic overflow in `_verifyReserveAndDebtLimits` will cause DOS for liquidity operations with large reserve/debt values","author":"dalitblue"},{"number":436,"title":"Missing Unchecked Block in Tick Crossing feeGrowthOutside Update Causes Swap DOS","author":"ranzo"},{"number":437,"title":"Accounting Inversion in D4 Pools: Borrow Increases Reserves While Payback Decreases Reserves","author":"ranzo"},{"number":446,"title":"D3/D4 payouts are misrouted to MoneyMarket when recipient is zero address","author":"0x04"},{"number":447,"title":"D4 Math Overflow in Quadratic Solver Causes DoS and Blocks Liquidations","author":"kkkkkk"},{"number":448,"title":"ERC721 Approvals Ignored in Position Management - EIP Violation","author":"kkkkkk"},{"number":449,"title":"Missing Interest Accrual During Pending Liquidation Transactions.","author":"ViquetourOnTop"},{"number":450,"title":"BigNumber + ROUND_UP Drift in MoneyMarket Borrow Accounting","author":"0x04"},{"number":451,"title":"`swapSingle(isCallback=false)` allows fee-on-transfer underpayment, draining pool reserves","author":"nitinaimshigh"},{"number":452,"title":"Eip violation due to missing UUPS safety guard in proxiableUUID() Function","author":"securehash1"},{"number":453,"title":"EIP violation due to missing onlyProxy Guard on UUPS upgrade functions","author":"securehash1"},{"number":454,"title":"Calldata layout mismatch for SKIP_TRANSFERS creates risk of revert in Callback","author":"securehash1"},{"number":455,"title":"Underflow in swap module due to unchecked Reserve subtraction","author":"securehash1"},{"number":456,"title":"Unchecked multiplication in fee growth calculation can lead to Overflow","author":"securehash1"},{"number":457,"title":"Missing underflow checks in removeLiquidity function","author":"securehash1"},{"number":458,"title":"Liquidator Can Seize Collateral Without Reducing Borrower Debt Due to Payback Rounding","author":"ShadSF"},{"number":459,"title":"Silent Arithmetic Overflow In Token Reserve Accounting.","author":"ViquetourOnTop"},{"number":461,"title":"Missing access control on critical administrative Functions in FluidDexV2D3AdminModule","author":"securehash1"},{"number":462,"title":"Inverse rounding in debt swaps allows risk free value extraction","author":"zubyoz"},{"number":465,"title":"Missing access control on multiple administrative functions in FluidMoneyMarketAdminModuleImplementation","author":"securehash1"},{"number":467,"title":"An approved receiver contract will brick (make non-transferable) a MoneyMarket position NFT for its owner","author":"Baazigar"},{"number":469,"title":"Read-only Reentrancy in payback allows clearing more debt than paid due to CEI Violation","author":"AkobirSec"},{"number":470,"title":"Critical Systemic Reentrancy in Perfect Operations Module (depositPerfect, borrowPerfect, paybackPerfect)","author":"AkobirSec"},{"number":471,"title":"Critical Read-only Reentrancy in swapIn allows draining Money Market due to CEI Violation","author":"AkobirSec"},{"number":472,"title":"Commented-Out Validation in Payback Allows Indefinite Overleveraged Positions","author":"0x_Taigong"},{"number":473,"title":"Unchecked multiplication overflow before mulDiv will cause incorrect sqrtPriceX96 \u2192 wrong HF calculation for users with D3/D4 positions as an attacker can trigger silent errors or reverts","author":"watsonclyde"},{"number":474,"title":"[MEDIUM-HIGH] Precision Loss in Pool Initialization allows First-Block Arbitrage due to ROUND_DOWN in BigMath","author":"AkobirSec"},{"number":475,"title":"[CRITICAL] D4 Smart Debt positions become permanently un-liquidatable leading to Protocol Insolvency when stored fees are insufficient","author":"AkobirSec"},{"number":477,"title":"Missing Slippage Protection in Multi-Step Operations","author":"0x_Taigong"},{"number":478,"title":"getApproved function does not revert for Nonexistent Tokens, violating EIP-721 Standard","author":"securehash1"},{"number":479,"title":"changeEmode function restricts access to NFT Owner Only, excluding approved Operators","author":"securehash1"},{"number":481,"title":"Payback Rounding-Up Can Preserve Borrowed Amount After Repayment, Breaking Debt Decrease Invariant","author":"ShadSF"},{"number":482,"title":"Missing Interest and price accrual on E-Mode Change","author":"securehash1"},{"number":486,"title":"Withdrawal Hook Reverts Even When Total Available Liquidity Is Sufficient","author":"nitinaimshigh"},{"number":487,"title":"`PendingTransfers` Never Cleared in `settle`, Causing `startOperation` to Always Revert","author":"JuggerNaut"},{"number":488,"title":"Users ERC20 tokens are stuck in moneyMarket contract due to improper input validation","author":"iamephraim"},{"number":489,"title":"LiquidateModule Incorrectly Reads Oracle Address from `_moneyMarketVariables`","author":"JuggerNaut"},{"number":491,"title":"`upgradeToAndCall` is marked `payable` but cannot receive ETH because it is called via a non\u2011payable `fallback`","author":"JuggerNaut"},{"number":493,"title":"Missing access control on updateD3DefaultPermissionlessDexCap will cause griefing and weakened risk limits for MoneyMarket users","author":"reentrantai"},{"number":494,"title":"Missing governance checks in updateOracle will cause oracle takeover for Money Market users","author":"reentrantai"},{"number":495,"title":"Fee growth global precision loss from BigNumber round-down during tick crossing causes permanent loss of accrued LP fees","author":"navie1230"},{"number":498,"title":"Malicious controller can manipulate `fetchDynamicFee` to extract value from swappers by returning inflated fees that bypass the dynamic fee kink system","author":"navie1230"},{"number":501,"title":"Hard Minimum Amount Check Temporarily Traps User Funds for High-Value Low-Decimal Tokens Like WBTC","author":"0xpetern"},{"number":502,"title":"Attacker Can Force Immediate Fee Decay Reset Through Minimal Swaps\"","author":"neme"},{"number":503,"title":"Stale historical `borrowExchangePrice` baked into `feeGrowthGlobal` in D4 pools causes systematic undervaluation of LP fee collateral, enabling premature liquidation","author":"ranzo"},{"number":507,"title":"Incorrect sentinel handling in settle causes payable no-op and ETH loss","author":"Vinay"},{"number":519,"title":"D1._swapIn uses swapped amtInAdjusted/amtOutAdjusted in reserve verification for token1\u2192token0 swaps","author":"Viridis"},{"number":521,"title":"Missing msg.value handling for D4 position Liquidations","author":"securehash1"},{"number":522,"title":"Operator precedence bug in max Positions Check allows bypassing position Limit","author":"securehash1"},{"number":523,"title":"Missing overflow check on `position debt amount` can lead to storage corruption and Fund Loss","author":"securehash1"},{"number":524,"title":"Missing Deadline Protection in Swap Operations","author":"alaskanking"},{"number":525,"title":"Swaps will revert when crossing ticks causing DoS affecting D3/D4 pool users","author":"Bozwkd"},{"number":527,"title":"Integer Overflow in D4 Debt Calculation Causes Permanent DoS for High-Value Positions","author":"aman123"},{"number":528,"title":"Exactly-Once Violation in operate: Non-Reverting Partial Execution Enables Double State Effects","author":"YF"},{"number":529,"title":"`BigMathMinified` systematic rounding bias leads to premature liquidations in MoneyMarket positions","author":"RV"},{"number":532,"title":"External liquidity call before clearing unaccounted state (Reentrancy) in `_callLiquidityLayer`","author":"D4N0GOTHACKED"},{"number":533,"title":"`BigMathMinified` truncation leads to total loss of small deposits in `MoneyMarket`","author":"RV"},{"number":534,"title":"Silent liquidity failure stores user amounts (catch writes user state)","author":"D4N0GOTHACKED"},{"number":535,"title":"Delegatecall admin implementation allows arbitrary code execution in `operateAdmin`","author":"D4N0GOTHACKED"},{"number":539,"title":"User-specified `to_` address is ignored in during borrow operations, forcing debt funds to `msg.sender`","author":"Um158057"},{"number":543,"title":"Liquidation DOS","author":"EddiePumpin"},{"number":545,"title":"`DexV2: settle(clear-all)` clears `pendingSupply` without verifying received amount, enabling `fee-on-transfer` underpayment","author":"nitinaimshigh"},{"number":547,"title":"[H-01] Irrecoverable Loss of Collateral in Smart Debt (D4) via Deterministic Repayment Blockage and Forced Liquidation","author":"HiroWatanabe"},{"number":548,"title":"Systematic Precision Loss in Fee Accumulation due to Division before Multiplication","author":"salebe17"},{"number":549,"title":"[High] Liquidity providers will lose access to their funds as `_removeLiquidity()` reverts on withdraw after sequential swaps","author":"Ramprasad4121"},{"number":550,"title":"Zero Interest for Lenders due to Precision Loss in Supply Rate Calculation","author":"salebe17"},{"number":551,"title":"Missing Transaction Expiration Check (Deadline) in Swap Operations","author":"salebe17"},{"number":552,"title":"Inaccurate share/debt accounting in PoolT1 due to lack of balance checks for Fee-on-Transfer tokens","author":"salebe17"},{"number":553,"title":"Silent Bit-Shift Overflow in LiquidityCalcs leads to Corrupted Accounting and Massive Loss of Funds","author":"RV"},{"number":554,"title":"User are denied of claiming any fee amount","author":"EddiePumpin"},{"number":555,"title":"DexV2 `settle()` credits stored balances and allows withdrawal even when Liquidity is paused","author":"zubyoz"},{"number":556,"title":"Lack of Timelock and Excessive Fee Caps in PoolT1 Admin Functions Enable Front-running and Griefing","author":"salebe17"},{"number":558,"title":"Dex balance can fall below recorded auth-seed + user-stored amounts (bookkeeping mismatch allows depletion of reserved auth seed)","author":"Cara"},{"number":560,"title":"Borrowers are susceptible to immediate liquidation after borrowing","author":"EddiePumpin"},{"number":562,"title":"Phantom credit on liquidity failure allows withdrawal of unbacked tokens","author":"zubyoz"},{"number":563,"title":"Fast-path settle transfers can reduce contract balance below reserved auth-seed, breaking accounting invariants","author":"inallhonesty"},{"number":564,"title":"Malicious users will steal all funds from the DexV2 protocol due to an asset inflation vulnerability in the settle function","author":"Albert_Mei"},{"number":566,"title":"Permanent DoS of Liquidation via Block Gas Limit Exceeded","author":"kkkkkk"},{"number":568,"title":"Oracle Price Manipulation via Spot Reserves in DexReservesFromLiquidity.sol allows for Predatory Liquidations","author":"salebe17"},{"number":569,"title":"Collateral value inflation in DexPegOracle via spot reserve manipulation allows for undercollateralized loans","author":"salebe17"},{"number":572,"title":"D4 liquidation with same payback and withdraw index reads wrong position after deletion reindexes the slot","author":"Ridden5839"},{"number":573,"title":"Infinite Proxy Protection Triggers Reentrancy Lock During Liquidity Callback","author":"rotanaj"},{"number":575,"title":"Malicious User will prevent liquidation for Protocol","author":"shivanshu814"},{"number":576,"title":"Liquidity Layer Failure will cause state desync for Dex Protocol","author":"shivanshu814"},{"number":577,"title":"Stale Chainlink price accepted without freshness validation enables over-borrow","author":"duan"},{"number":578,"title":"Borrower collateral can be drained through cascading partial liquidations due to missing health factor lower bound check in post-liquidation validation","author":"x86sgn"},{"number":579,"title":"Pause Bypass in FluidDexV2.settle: Liquidity failure is converted to IOU credit instead of revert","author":"duan"},{"number":581,"title":"Silent Precision Loss in BigMath Unsafe Paths Can Cause Protocol-Wide Accounting Drift","author":"RoushanGoswami"},{"number":583,"title":"User Callback Is Invoked Before Final Internal State Settlement in Dex V2 Operations","author":"RoushanGoswami"},{"number":585,"title":"Borrow Interest Accrual Miscalculation Due to Inconsistent Liquidity-Derived Rate Computation","author":"RoushanGoswami"},{"number":588,"title":"Cross-pool economic harm via non-callback `settle()` under-delivery on shared malicious token inventory","author":"JohnLaw"},{"number":590,"title":"Missing Decimal Factor in sqrtPriceX96 Price Ratio Calculation","author":"ViquetourOnTop"},{"number":592,"title":"Missing Event Emission","author":"neme"},{"number":594,"title":"Swap Fees Permanently Leak from Fluid Liquidity Layer in D3 Pools","author":"dexters"},{"number":597,"title":"D3 and D4 cap setters use token index and decimals without validating token listing","author":"D4N0GOTHACKED"},{"number":598,"title":"Liquidation rejects paybacks under $0.01, leaving dust positions unliquidatable","author":"D4N0GOTHACKED"},{"number":603,"title":"Whitelisted user will desynchronize Liquidity Layer accounting for the DEX contract as settle() optimization skips LIQUIDITY.operate()","author":"sftwr"},{"number":604,"title":"Dynamic fee override can be bypassed via oversized controller data","author":"fullcounterhunter"},{"number":607,"title":"Timestamp Collision in helpers.sol Allows Users to Evade Interest and Fees","author":"Anandhan"},{"number":608,"title":"BigMathMinified logic error causes \"Phantom Inflation\" where values increase even with perfect compression","author":"Lemon996z"},{"number":609,"title":"Permissionless Pool Initialization Is Impossible Due to Hard Whitelist Gate","author":"0xpetern"},{"number":613,"title":"Price changes causes cap check underflow revert, DoS-ing D3 withdraw or D4 payback","author":"0xCrypt0nite"},{"number":615,"title":"A swapOut caller will cause accounting corruption in D4 via unchecked payback underflow","author":"sleo"},{"number":616,"title":"A swapOut caller will cause incorrect fee accounting in D4 via inconsistent rounding","author":"sleo"},{"number":619,"title":"Inconsistent revert behavior between token0 and token1 fee processing may cause avoidable liquidation failures","author":"mkXploit"},{"number":620,"title":"Malicious User will Evade Protocol Fees and Debt for Protocol by Splitting Transactions due to BigMath Precision Loss","author":"RV"},{"number":624,"title":"Stored-claim fallback uses `to_` key while consumption uses `msg.sender` key, causing permanent claim stranding for EOA recipients","author":"JohnLaw"},{"number":625,"title":"Missing slippage validation in D4 payback enables liquidator value loss through unvalidated actual payback amounts","author":"makeWeb3safe"},{"number":629,"title":"ERC721 Compliance: Approved Operators Blocked from operate()","author":"kkkkkk"},{"number":630,"title":"D4 Fee Mismatch: Inflationary Revenue Collection","author":"kkkkkk"},{"number":631,"title":"Integer Overflow in withdraw() Allows Users to Drain Protocol Funds","author":"dexters"},{"number":632,"title":"`rebalance()` reentrancy window can wipe `_unaccountedBorrowAmount`","author":"JohnWeb3"},{"number":633,"title":"NET_TRANSFERS \u201cnet tokens in\u201d branch ignores `to_` and nets outgoing value against `msg.sender` (router/relayer theft risk)","author":"JohnWeb3"},{"number":634,"title":"Loss/Lock of User Funds - settle() Fallback Accounting Failure - settle() - FluidDexV2 (main.sol)","author":"Rolando"},{"number":635,"title":"Integer Overflow in payback() Allows Debt Inflation and Protocol Drainage","author":"dexters"},{"number":637,"title":"tokenURI Not Updated Per NFT ID, Preventing NFT-Specific Metadata Allowing for Custom Graphics on NFT marketplaces","author":"0xBoraichoT"},{"number":638,"title":"Missing minAmountOut Protection on Liquidation Allows Value Slippage","author":"lanrebayode77"},{"number":639,"title":"Liquidation of high-LT collateral in mixed portfolios may decrease health factor","author":"Slayer"},{"number":641,"title":"D3 Liquidation Is Split-Dependent: Repeated Rounding Bias Lets Liquidators Extract More Collateral for the Same Total Repay","author":"Icarus"},{"number":642,"title":"D3/D4 `initialize()` mutates pool state without acquiring the per-pool `PoolLock`","author":"JohnWeb3"},{"number":646,"title":"EIP-1153 transient storage dependency will brick deployments on non-Cancun/EIP-1153 chains (Plasma)","author":"JohnWeb3"},{"number":647,"title":"Admin `upgradeToAndCall` is payable but routed through a non-payable fallback, blocking ETH-funded upgrade initialization","author":"JohnWeb3"},{"number":649,"title":"Overflow/revert DoS in HF math from large raw amounts and multi-term multiplications","author":"JohnWeb3"},{"number":650,"title":"Governance derived from LIQUIDITY's EIP-1967 admin slot can be non-callable (e.g., ProxyAdmin), permanently bricking DexV2 admin controls","author":"JohnWeb3"},{"number":653,"title":"Dewhitelisted Users Fee Extraction Via Settle Function","author":"ViquetourOnTop"},{"number":654,"title":"`rebalance()` unsafe `uint256 -> int256` casts can overflow/revert or miscompute liquidity deltas","author":"JohnWeb3"},{"number":657,"title":"Missing bit shift on allowedMaxYieldJumps extraction makes rate cap 32x more permissive than intended","author":"dahmon"},{"number":658,"title":"Incorrect rounding direction in _getAmountIn systematically undercharges swappers draining LP value","author":"dahmon"},{"number":659,"title":"Critical Arithmetic Underflow in divBigNumber leads to Infinite Exponentiation and Total Loss of Precision","author":"Lemon996z"},{"number":661,"title":"Arbitrary from_ in liquidityCallback Allows Draining Victim Allowances","author":"Um158057"},{"number":665,"title":"DEX V2 swap\u2011driven DEX debt can be amplified to extract LP yield under production rate configs","author":"zubyoz"},{"number":668,"title":"Attackers will create unprofitable liquidation scenarios leading to bad debt accumulation for the protocol","author":"Jumcee"},{"number":670,"title":"D3/D4 health-factor path panics on valid positions and blocks core MoneyMarket actions","author":"bratwork"},{"number":671,"title":"D3 cap usage is not fully released on close, causing cumulative cap drift and eventual pool lockout","author":"bratwork"},{"number":672,"title":"MoneyMarket/Liquidity debt rounding mismatch creates unpayable phantom debt that permanently locks user collateral","author":"rajatbeladiya"},{"number":676,"title":"Missing supply-side discrepancy tracking in `settle()` fallback causes `rebalance()` to compute incorrect Liquidity Layer adjustments, freezing user funds","author":"Cryptor"},{"number":679,"title":"Any trader can abnormally raise the dynamic fee rate for subsequent traders and increase their trading costs.","author":"ZeroTrust"},{"number":681,"title":"JIT Liquidity Attack Enables Fee Theft and Liquidation DOS Creating Bad Debt","author":"yoooo"},{"number":682,"title":"Lost of funds during withdrawal of borrow","author":"EddiePumpin"},{"number":683,"title":"Users can continue increasing borrows after borrowing has been disabled.","author":"ZeroTrust"},{"number":684,"title":"Users can continue increasing deposits after collateral functionality has been disabled.","author":"ZeroTrust"},{"number":687,"title":"Inconsistent Position Reindexing May Break Fee Accounting","author":"Negin"},{"number":688,"title":"Unvalidated Tick Decoding May Lead to Incorrect Position Validations","author":"Negin"},{"number":691,"title":"DexV2 mints redeemable stored credit when Liquidity payout fails, enabling future reserve drain","author":"nitinaimshigh"},{"number":692,"title":"Inconsistencies in handling repay amounts can cause collateral to be locked and positions cannot be closed","author":"0xDemon"},{"number":693,"title":"BigMath Round-Trip Inconsistency Causes Fee Accounting Corruption and Stuck LP Funds","author":"EVDoc"},{"number":694,"title":"Partial Liquidation Can Trap Users in an Unrepayable Debt State","author":"0xpetern"},{"number":696,"title":"Heartbeat-expired oracle reads fresh price while storage remains stale, causing inconsistency between view functions and storage state","author":"EVDoc"},{"number":697,"title":"No incentive to liquidate underwater positions when collateralValue < debtValue leads to bad debt","author":"elolpuer"},{"number":698,"title":"Pool Isolation - Malicious Token Callback Corrupts Other Pools","author":"Rea"},{"number":700,"title":"User will extract positive carry from D4 pools","author":"fgh56ty"},{"number":702,"title":"Malicious callback contract will manipulate protocol state during locked operations by exploiting missing reentrancy protection on operate function","author":"x86sgn"},{"number":703,"title":"BigMath Compression - Uncompensated Loss Of Small Fee Increments","author":"Rea"},{"number":704,"title":"Smart Debt Math - Uncompensated Rounding Divergence","author":"Rea"},{"number":705,"title":"A malicious D3 pool creator will socialize token-accounting shortfall to users of other D3 pools","author":"0x04"},{"number":706,"title":"Missing msg.sender in swap params allows attacker to bypass per-user fee tiers via controllerData spoofing","author":"hackcat"},{"number":709,"title":"Liquidator will worsen health factor of underwater positions, accelerating bad debt accumulation for the protocol","author":"hackcat"},{"number":713,"title":"Funds stored in the contract cannot be withdrawn by users","author":"EddiePumpin"},{"number":714,"title":"Arithmetic underflow in _calculateCollateralValues when CF=0 bricks entire NFTs including zero-debt positions","author":"maigadoh"},{"number":715,"title":"D4 borrow with to = address(0) defaults to MoneyMarket not the caller, leaving borrowed funds trapped in the MoneyMarket contract","author":"LeoGold"},{"number":716,"title":"Missing check on assigning address to immutable variables can permanently brick protocol contracts","author":"FlameHorizon1"},{"number":717,"title":"Instant UUPS upgrades provide no rollback or user exit window for faulty implementations","author":"creatorexr"},{"number":719,"title":"No Check For Sequencer Uptime When Fetching Chainlink Prices","author":"0xquanthunter"},{"number":720,"title":"Division by Zero in Redstone Oracle Rate Inversion","author":"0xquanthunter"},{"number":721,"title":"Missing Negative/Zero Price Validation in Chainlink Oracle","author":"0xquanthunter"},{"number":722,"title":"Oversized controllerData forces dynamic fee fetch OOG, bypassing LP fees to zero","author":"maigadoh"},{"number":723,"title":"Missing Chainlink Oracle Staleness Checks","author":"0xquanthunter"},{"number":724,"title":"[M-01]  Safety Margin bypass in Big Number Compression","author":"Peter3144"},{"number":725,"title":"HF can be computed with staled exchange prices","author":"EddiePumpin"},{"number":727,"title":"Missing Health Factor Check in D4 Position Creation","author":"inspecktor"},{"number":728,"title":"Zero address Permit Bypass in `_allowViaPermitEIP2612` in `fToken::main.sol` Enables Unauthorized Allowances","author":"0xfallin1"},{"number":731,"title":"Incorrect liquidationPenalty Limit During D3_POSITION_TYPE and D4_POSITION_TYPE Liquidation","author":"inspecktor"},{"number":732,"title":"Missing Reentrancy Guard in `mintWithSignatureEIP2612` leads to State Manipulation","author":"Um158057"},{"number":734,"title":"Borrower can grief/DoS partial liquidation by front-running with a small repay","author":"velev"},{"number":735,"title":"Attacker will DoS swaps for D3 pool traders and LPs","author":"jongwon"},{"number":738,"title":"No deadline parameter in any DEX V2 operation allows validators to exploit stale transactions","author":"velev"},{"number":739,"title":"`tokenURI()` returns empty string, breaking ERC721Metadata compliance and NFT marketplace integration","author":"velev"},{"number":742,"title":"Liquidity providers (LPs) on DexV2 earn yield generated by the Liquidity protocol\u2014without having to actively supply liquidity or take on additional risk.","author":"0xBoraichoT"},{"number":745,"title":"Incorrect rounding in _processNormalBorrowAction can block closing borrow position and lock users collateral","author":"iamephraim"},{"number":746,"title":"DexV2 settle() Fast-Path Skips Liquidity Bookkeeping, Allowing MoneyMarket maxUtilization Bypass in Same Transaction","author":"nitinaimshigh"},{"number":747,"title":"function swapOut() will lead to reserves calculation error","author":"cu5t0mPe0"},{"number":751,"title":"Unprivileged User Can Arbitrarily Relocate Liquidity Between Dex and Liquidity Layer, Overriding rebalance()","author":"Vinay"},{"number":753,"title":"Solvency Check Bypass in Withdrawal Fast Path Leads to Protocol Drain","author":"EtherEngineer"},{"number":755,"title":"Liquidation DoS in D3/D4 Positions via Asymmetric Fee Concentration","author":"yoooo"},{"number":758,"title":"MEV Attackers Can Reduce Liquidation Recovery via Sandwiching and Harm Liquidators","author":"ZeroTrust"},{"number":759,"title":"Missing `msg.value` Validation/Refund in ERC20 Settlement Paths Can Permanently Trap ETH in DexV2","author":"kimnoic"},{"number":761,"title":"Zero Geometric Mean in payback() and borrow() Causes Permanent DoS of Borrow, Repayment, and Liquidation","author":"Bizarro"},{"number":762,"title":"Price Inconsistency in Reserve/Debt Conversion Functions Causes Accounting Desync.","author":"Bizarro"},{"number":763,"title":"HF calcualtion includes non-isolated collateral when isolated mode is active","author":"Bizarro"},{"number":767,"title":"Dynamic-Fee Controller will permanently block swaps for dynamic-fee pools","author":"nitinaimshigh"},{"number":768,"title":"Full liquidation config bricks all liquidations","author":"Tigerfrake"},{"number":769,"title":"Emode transition is blocked for users with solely normal supply and normal borrow positions due to rigid collateral/ debt class check","author":"slowpoke"},{"number":770,"title":"Attacker will cause protocol bad debt by manipulating D4 pool price before payback to decouple payback composition from oracle-derived debt valuation","author":"ZeroTrust"},{"number":771,"title":"Transient Storage Pollution in `startOperation` allows Malicious Actors to DoS Money Market and Leak State between Positions","author":"RV"},{"number":772,"title":"_positionFeeStored Not Updated After D4 Fee Collection During Liquidation","author":"inspecktor"},{"number":778,"title":"getmaxliquditypertick overcounts tick range by 1 when mintick/ maxtick is not divisible by tickspacing","author":"slowpoke"},{"number":779,"title":"User will create protocol liability without token transfer when liquidity layer fails","author":"x86sgn"},{"number":780,"title":"`settle` does not enforce that settled amounts are within pending supply/borrow, which could lead to protocol overpayment and users draining funds by claiming withdrawals or borrows without sufficient pending entitlement","author":"uba"},{"number":781,"title":"Borrow logic in D4 Module is broken","author":"oxwhite"},{"number":784,"title":"`addOrRemoveTokens` can remove tokens up to total auth-added amount without a solvency check, which could lead to the contract becoming insolvent for user stored balances (users unable to withdraw what they are owed)","author":"uba"},{"number":786,"title":"Timestamp Overflow in DexV2 leads to Permanent Denial of Service (OperationNotActive)","author":"Holmes7002"},{"number":789,"title":"Reward Rate Manipulation via `notifyRewardAmount` in `stakingRewards::main.sol` Enables Unfair Reward Extraction","author":"0xfallin1"},{"number":791,"title":"Fee growth outside subtraction can revert during tick crossing due to BigMath encode/decode precision loss, blocking swaps","author":"Jiberish"},{"number":795,"title":"Inverted Debt Reserve Accounting in DEX V2 Smart Debt Pools (D2 and D4) Allows Pool Draining & DoS","author":"0xbzbee42"},{"number":797,"title":"Fee Growth Increment Loss at Moderate Values","author":"sharthak18"},{"number":798,"title":"A caller will corrupt stored branch debt accounting for the protocol","author":"SecurityAgentOZ"},{"number":800,"title":"A borrower will brick debt closure for MoneyMarket position holders","author":"SecurityAgentOZ"},{"number":802,"title":"D3 vs D4 Pools Produce Different Swap Outputs Due to Exchange Price Spread, Making D4 Pools Economically Non-Viable","author":"x0lohaclohell"},{"number":803,"title":"Asymmetric Exchange Price Drift Causes Unfair Swap Pricing and Systematic User Losses","author":"x0lohaclohell"},{"number":807,"title":"Liquidation fee fallback can revert early on token1 shortfall even when residual is within accepted $0.01 dust","author":"antigone4224"},{"number":809,"title":"DoS from large position counts in health factor calculations","author":"K42"},{"number":810,"title":"Lack of Slippage On Liquidation May Result To Losses For Liquidators","author":"yoooo"},{"number":811,"title":"Users will drain admin seed liquidity causing insolvency","author":"x86sgn"},{"number":812,"title":"_useFeeStoredForLiquidation Reverts When Token1 Fees Are Insufficient, Blocking D3/D4 Collateral Liquidations","author":"maxim371"},{"number":815,"title":"Deeply Underwater D3 Position Permanently Unliquidatable","author":"Theseersec"},{"number":816,"title":"D3 Liquidation Withdrawals Execute at Manipulated Pool Price with Zero Slippage Protection, Causing Unfair Collateral Seizure","author":"Theseersec"},{"number":817,"title":"Attacker will drain real ETH from the DEX pool by minting unbacked internal credits via unchecked fallback after Liquidity Layer revert","author":"Um158057"},{"number":818,"title":"Liquidator can manipulate D3 pool price to seize more tokens from user during liquidations","author":"0xCrypt0nite"},{"number":820,"title":"D4 payback() Whitelist Modifier Contradicts Design Intent, Can Block D4 Liquidations","author":"zvizr"},{"number":821,"title":"Smart Debt Positions in Low-Volume Pools Cannot Be Liquidated Due to Zero Fee Accumulation","author":"Theseersec"},{"number":824,"title":"Swaps' submethods determine swap direction based on prices which may be equalized causing corrupted price, amounts and fees","author":"BozhidarBonev"},{"number":825,"title":"Liquidation Failure via Minimal Repay Attack","author":"SOPROBRO"},{"number":827,"title":"Economic Denial of Service via Collateral Fragmentation leads to Bad Debt","author":"taticuvostru"},{"number":828,"title":"Mode-Dependent Price Validation Allows Operate-Path DoS While Liquidation Remains Enabled","author":"nitinaimshigh"},{"number":831,"title":"D3 Collateral + Borrow Flow Can Revert with Arithmetic Underflow when Oracle Returns Zero Price for a Token","author":"uba"},{"number":832,"title":"Orphaned Stored Fees on D3/D4 Position Deletion","author":"maxim371"},{"number":833,"title":"_verifyAmountLimits() Applied to Protocol-Computed Full-Exit Amounts Permanently Locks Dust Positions in Both Supply and Borrow","author":"Theseersec"},{"number":835,"title":"Cross-Contract State Reentrancy in operate() allows Collateral Theft and Bad Debt via DEX Callback","author":"Peter3144"},{"number":836,"title":"GhostETH Accumulation leading to Protocol Deadlock via Interest Rate Truncation","author":"Um158057"},{"number":837,"title":"Market/oracle price disparity will block HF checks for D3/D4 positions","author":"Merlinsan"},{"number":840,"title":"Liquidation is favourable to liquidatee than liquidators","author":"EddiePumpin"},{"number":841,"title":"Silent Overflow in `BigMathMinified.fromBigNumber()` Enables Price Manipulation and Fund Drainage","author":"Zeethefist"},{"number":842,"title":"D4 borrowers can manipulate LP token ratio before payback","author":"adeolu"},{"number":844,"title":"BigMath Precision Loss in Withdrawal Limit Calculation Allows Protocol Loss","author":"playerOfGames"},{"number":845,"title":"Chainlink Oracle Does Not Validate Price Staleness","author":"playerOfGames"},{"number":846,"title":"Fee Growth Underflow Enables DEX Contract Drainage","author":"x0lohaclohell"},{"number":847,"title":"Oracle Price Validation Asymmetry Between operate() and liquidate()","author":"playerOfGames"},{"number":848,"title":"Oracle vs Pool Price Mismatch in D3/D4 Liquidation Causes Liquidation DoS","author":"aman"},{"number":849,"title":"Cross-Contract Reentrancy via liquidityCallback Allows State Manipulation","author":"playerOfGames"},{"number":850,"title":"Oracle Health Check Bypass When Depositing Collateral Allows Underwater Positions to Avoid Liquidation","author":"playerOfGames"},{"number":861,"title":"D4 Phantom Liquidity Enables Bad Debt Creation","author":"x0lohaclohell"},{"number":862,"title":"Attacker will drain funds from Liquidity Providers by manipulating debt reserves in D4 pools.","author":"TheoryHunter"},{"number":863,"title":"Extreme D4 ticks cause int256 overflow in reserve math, reverting two-token ops","author":"crab0saurus"},{"number":864,"title":"Liquidator steals D3 collateral via stale numberOfPositions during same-index D4 liquidation","author":"crab0saurus"},{"number":867,"title":"Attacker will bypass swap fees in D4 pools by reclaiming them via incorrect pending supply credit.","author":"TheoryHunter"},{"number":868,"title":"MEV JIT Liquidity Captures Most LP Fees","author":"Baazigar"},{"number":869,"title":"Attacker can permanently DoS D4 pools via integer overflow in quadratic debt reserve calculations","author":"TheoryHunter"},{"number":871,"title":"Missing Price Staleness Check in Chainlink Oracle","author":"WarwickEF"},{"number":872,"title":"Bad debt socialization, late suppliers suffer partial or total loss during bank run exits","author":"zubyoz"},{"number":873,"title":"Min Tick - 1 overwrites sqrtPrice leading to future wrong sqrtPrice","author":"0iadx"},{"number":874,"title":"Tick crossing can be skipped due to rounded down sqrtPriceX96 storage + equality gated crossing leading to wrong feeGrowthOutside and liquidity accounting","author":"0iadx"},{"number":876,"title":"Suboptimal Fee Liquidation Order Reduces Health Factor Improvement","author":"SOPROBRO"},{"number":877,"title":"Triple Rounding Down in `liquidate()` Causes Systematic Value Loss During Liquidations","author":"0xMafiaBug"},{"number":880,"title":"Rubyglask - D1._swapIn() swaps amtInAdjusted and amtOutAdjusted in _verifyToken0Reserves for !swap0To1 direction","author":"Rubyglask"},{"number":881,"title":"Copy-paste bug in VaultT2/VaultT4 `_colOperatePerfectBefore` validates `colToken0MinMax_` twice, leaving `colToken1MinMax_` unchecked, enabling MEV sandwich attacks on token1 deposits","author":"Rubyglask"},{"number":883,"title":"Debt tokens in D3 LP positions are double counted as collateral.","author":"ElmInNyc99"},{"number":885,"title":"Systematic Ghost Debt Accumulation via Unconditional Rounding in BigMathMinified Library","author":"ArkheionX"},{"number":887,"title":"Type Confusion between Debt Shares and Debt Amount in VaultT3/T4 Max Payback","author":"ElmInNyc99"},{"number":888,"title":"D4/D3 Positions Become Unliquidatable When Accrued Fees Are Zero","author":"NOTTIBOY137"},{"number":889,"title":"Overflow in Smart Debt Quadratic Formula Blocks Liquidation of Large D4 Positions","author":"NOTTIBOY137"},{"number":890,"title":"BigNumber Precision Mismatch Between Global Fee Growth and Tick Fee Growth Causes Inflated Fee Calculations","author":"NOTTIBOY137"},{"number":891,"title":"Checked Arithmetic in Cap Tracking Causes Permanent DoS on Isolated Collateral Withdrawal","author":"NOTTIBOY137"},{"number":893,"title":"Absence of Debt-Transfer Hooks in ERC721 results in Address-to-Position Mismatch and Protocol-wide Bad Debt","author":"gelenbedalen"},{"number":897,"title":"[H-01] Silent Data Corruption in BigMathMinified due to Lack of Bit-Width Validation in Packing Logic","author":"gelenbedalen"},{"number":898,"title":"D4 `payback()` retains `_onlyWhitelistedUsers` modifier despite removing all other liquidation-blocking checks, preventing Money Market from liquidating D4 debt positions and causing irrecoverable bad debt","author":"Cryptor"},{"number":899,"title":"LP Fees Are Charged But Not Accounted When Swaps Traverse Zero Active Liquidity Regions","author":"urek0x0"},{"number":902,"title":"[M-02] Inconsistent rebalance Execution in DexV2AdminModule can Lead to Significant Interest Mismatch","author":"gelenbedalen"},{"number":903,"title":"Flawed Revenue Calculation Logic Permits Extraction of User Principal as Protocol Profit","author":"gelenbedalen"},{"number":904,"title":"Bit-mask Mismatch between LiquidityCalcs and DEX Storage enables Permanent DoS of Exchange Price Updates","author":"gelenbedalen"},{"number":905,"title":"DexV2 Timestamp Overflow leading to incorrect Center Price Shifting and Potential Loss of Funds","author":"gelenbedalen"},{"number":906,"title":"[M-01] VaultFactory::spell Allows Ownership Bypass and Arbitrary State Manipulation via Delegatecall","author":"gelenbedalen"},{"number":907,"title":"Unconditional +1 Rounding in D4 Payback Can Make Exact Debt Repayment Impossible (Functional DoS)","author":"gelenbedalen"},{"number":908,"title":"Cumulative Rounding Manipulation in deposit and withdraw Enables Collateral Inflation and Fee Drainage","author":"gelenbedalen"},{"number":910,"title":"Precision Loss in LiquidityCalcs Enables Systematic Interest Evaporation via Frequent Updates","author":"gelenbedalen"},{"number":911,"title":"Manipulated Debt Absorption Leads to Artificial Socialization of Losses and LP Fund Drainage","author":"gelenbedalen"},{"number":912,"title":"Stagnant Exchange Price Accrual in VaultT1 Enables Unfair Liquidations and User Collateral Theft","author":"gelenbedalen"},{"number":919,"title":"Dynamic fee calculation underflows when stepDynamicFee_ approaches SIX_DECIMALS","author":"intuitek"},{"number":920,"title":"Liquidation position index collision allows unintended collateral selection after position deletion","author":"intuitek"},{"number":921,"title":"Unchecked ry_ * Q96 multiplication in D4 debt calculation can overflow for large reserves","author":"intuitek"},{"number":926,"title":"Operation lock not bound to initiator","author":"r0bert"},{"number":931,"title":"`UUPS` `proxiableUUID` callable via proxy","author":"r0bert"},{"number":934,"title":"Liquidity fallback credits IOUs","author":"r0bert"},{"number":936,"title":"Reentrancy via liquidity callback allows nested `operate` during `settle` and accounting manipulation","author":"Tupaia"},{"number":938,"title":"Inconsistent liquidity callback payloads and addresses in DexV2 \u2192 Liquidity.operate calls lead to malformed callbackData and mis-decoding in FluidDexV2::liquidityCallback()","author":"Tupaia"},{"number":940,"title":"design flaw in liquidation incentives leading to bad debt accumulation and protocol insolvency risk","author":"Tupaia"},{"number":949,"title":"Liquidators can earn extra fees when liquidating a debt position backed by smart collateral","author":"SarveshLimaye"},{"number":950,"title":"A liquidator will be unable to fully repay insolvent debt, leaving bad debt for suppliers","author":"Thisisit"},{"number":952,"title":"`_unaccountedBorrowAmount` State Variable Not Updated Correctly Leads To Double Accounting Risk","author":"ElmInNyc99"},{"number":953,"title":"Small Supply Amounts Become Unwithdrawable Due to Rounding","author":"0xBug_X"},{"number":954,"title":"Valid liquidations revert instead of allowing dust remainder","author":"0xRstStn"},{"number":956,"title":"HardCoded Limit in _tenPow Function Causes DoS for Common DeFi assets and Persistent Precision Loss","author":"Peter3144"},{"number":958,"title":"Hard-coding max collateral and debt class can render `FluidMoneyMarketAdminModuleImplementation::listEmode` useless","author":"EddiePumpin"},{"number":959,"title":"Users can earn fees from untrue liquidity","author":"theweb3mechanic"},{"number":961,"title":"Incorrect `numTicks` in `_getMaxLiquidityPerTick` (Over-Conservative Cap)","author":"Rizalfahmi"},{"number":962,"title":"D3/D4 Liquidation Uses Pool Price for Token Split While Post-Liquidation HF Check Uses Oracle Price, Creating Accounting Inconsistency","author":"Pelz"},{"number":963,"title":"_tenPow Hardcoded Limit Creates Functional Dead Zone for Standard Low-decimal Tokens (e.g, GUSD, EURS), Leading to Protocol DOS","author":"Peter3144"},{"number":969,"title":"Any user will trigger deterministic D4 debt-path DoS for D4 position owner","author":"TradingViews"},{"number":972,"title":"Any caller of rebalance() will cause permanent unbacked debt and protocol insolvency for Vault users and Liquidity providers","author":"StevenJ"},{"number":977,"title":"Overly restrictive price impact check in dynamic fee update leads to denial of swaps for volatile token pairs","author":"AstarAudits"},{"number":979,"title":"Off-by-one rounding in `_getMaxLiquidityPerTick` leads to unnecessarily restrictive liquidity cap per tick","author":"AstarAudits"},{"number":983,"title":"`_afterIsolatedCollateralFullWithdraw` ignores D4 positions when checking remaining isolated collateral","author":"0xrox"},{"number":984,"title":"Missing `>> 5` right-shift in `fluidCappedRate.sol` will cause 32x rate cap amplification, allowing inflated collateral valuations for Money Market borrowers","author":"hexnikk"},{"number":986,"title":"`rebalance()` Permanently Blocked When Liquidity Utilization Is Near Max, Causing Interest-Free Borrowing and Lender Fund Lockup","author":"velev"},{"number":987,"title":"Asymmetric rounding in D3 cap accounting causes irreversible utilization drift","author":"JohnLaw"},{"number":988,"title":"Rebalance drains local balance backing outstanding stored claims","author":"JohnLaw"},{"number":989,"title":"Exact-balance `settle` routing can cause deterministic no-progress withdrawals under LL stress","author":"JohnLaw"},{"number":991,"title":"Share Inflation Attack in deposit() Allows First Depositor to Steal Subsequent Depositors' Tokens","author":"AkobirSec"},{"number":994,"title":"Missing Self-Liquidation Guard Allows Position Owner to Extract Protocol Bonus","author":"AkobirSec"},{"number":995,"title":"Fee-on-Transfer Tokens will cause a Denial of Service for Liquidity Operations as the Liquidity Layer strictly enforces balance checks","author":"eat-the-sky"},{"number":996,"title":"Fee-on-Transfer Tokens Break deposit() Accounting Leading to Pool Insolvency","author":"AkobirSec"},{"number":997,"title":"Self-Liquidation Allows Borrowers to Extract Liquidation Bonus While Leaving Bad Debt","author":"AnomX"},{"number":998,"title":"One-sided positions are blocked because `_addLiquidity` does not account for the case when the actual price is above a tick but rounded down to below it","author":"0xmechanic"},{"number":999,"title":"Liquidation path in `_getPrice` accepts price range that `_calculateSqrtPriceX96` cannot process, reverting D3/D4 health factor checks","author":"hexnikk"},{"number":1000,"title":"MoneyMarket liquidation does not allow slippage bounds for D3 collateral withdraw, enabling MEV sandwiching of liquidators","author":"AV"},{"number":1003,"title":"Deployment-address placeholders in core modules","author":"Bala1796"},{"number":1005,"title":"D4 Borrow Tokens Permanently Locked in _userStoredTokenAmount When Liquidity Layer Fails","author":"folip"},{"number":1007,"title":"A malicious borrower can permanently DoS full repay and full liquidation for users sharing the same borrow cap","author":"unineko"},{"number":1008,"title":"Delegatecall to Hardcoded Implementations","author":"Manax"},{"number":1009,"title":"Incorrect rounding logic in FluidSmartLending will cause systematic asset theft and Denial of Service for Users as an attacker will exploit the rounding direction","author":"NovaTheMachine"},{"number":1010,"title":"Precision loss in BigMathVault will cause solvency bypass for Users as an attacker will create debt positions that round to zero","author":"NovaTheMachine"},{"number":1012,"title":"ERC-721 transfer lacks HF checks, enabling attacker to transfer debt-only NFT to victim","author":"Blackdruid"},{"number":1013,"title":"Undocumented X86 Nominal Cap Creates Structural Liquidity Ceiling for High-Supply ERC-20 Tokens","author":"Null_logic"},{"number":1014,"title":"Fee-on-transfer borrow tokens cause debt overbooking creating systematic undercollateralization for borrowers as protocol records gross debt while delivering net proceeds","author":"agent_mino"},{"number":1015,"title":"Borrowers will suffer complete loss of repayment funds when Liquidity Layer interaction fails","author":"eryxxxxx"},{"number":1016,"title":"Liquidators cannot liquidate dust positions causing permanent bad debt for the protocol","author":"eryxxxxx"},{"number":1021,"title":"D3/D4 caps ignore stored fees, allowing cap-bypass via fee crystallization + re-deposit","author":"fuzious"},{"number":1022,"title":"Asymmetric Oracle Price Bounds Cause DoS for HF-Gated Actions","author":"fuzious"},{"number":1023,"title":"Positive rebasing token yields are misaccounted as protocol revenue, enabling ongoing supplier yield theft","author":"agent_mino"},{"number":1024,"title":"Anyone can set the fees and whitelist for D3 dex","author":"Audinarey"},{"number":1025,"title":"Dynamic fee override bypass via oversized controllerData (controller call fails","author":"AV"},{"number":1028,"title":"Governance key has arbitrary delegatecall powers across multiple systems","author":"Bala1796"},{"number":1030,"title":"Deterministic Precision Downgrade in Share Accounting Due to 9-Decimal Internal Normalization","author":"Null_logic"},{"number":1031,"title":"updating global dex caps does not affect already existing positions with permissionless tokens","author":"slowpoke"},{"number":1034,"title":"\"Not for prod\u201d code can be operationally enabled if governance whitelists it.","author":"Bala1796"},{"number":1035,"title":"15-bit timestamp wrap causes stale dynamic-fee decay, enabling directional fee mispricing and protocol/LP fee loss (D3/D4)","author":"Icarus"},{"number":1036,"title":"Malicious Controller will permanently block swaps for all pool users","author":"Leaningone"},{"number":1037,"title":"irrecoverable fee remains in the D4 position even after the D4 debt cleared & irrecoverable collateral is recorded in D3 due to a dust-level normal borrow","author":"slowpoke"},{"number":1039,"title":"Incomplete/stubbed protocol components present","author":"Bala1796"},{"number":1042,"title":"The attacker manipulates the position index via front-running, causing the user to operate on an incorrect position","author":"klaus"},{"number":1043,"title":"{actor} will {impact} {affected party}","author":"frankauditcraft"},{"number":1046,"title":"Changing Emode should not be allowed when the nft is liquidatable","author":"0xPhantom2"},{"number":1049,"title":"Unsafe math library documents known bugs and uses stop() in control flow","author":"Bala1796"},{"number":1050,"title":"Wallet callback trust model is fragile by design","author":"Bala1796"},{"number":1051,"title":"D4 whitelist gating will cause delayed liquidation for D4 debt positions under stress conditions","author":"theholymarvycodes"},{"number":1052,"title":"Liquidator will cause liquidation DoS and bad debt for the protocol as BigMathMinified rounding + insufficient +10 wei buffer fails against normal swap rounding","author":"oIKNg8y"},{"number":1053,"title":"maxLiquidityPerTick is calculated smaller than actual value","author":"klaus"},{"number":1054,"title":"Liquidator/owner will cause arbitrary execution and fund loss for the protocol as periphery/liquidation, buyback, and wethWrapper have onlyOwner spell functions","author":"oIKNg8y"},{"number":1058,"title":"Liquidator will suffer MEV loss as vaultLiquidation resolver allows slippage_ = 0 and insufficient minOut protection","author":"oIKNg8y"},{"number":1061,"title":"Ineffective Slippage Protection Due to Post-Check Fee Subtraction in FluidDexV2D3 Deposit Function","author":"0xBug_X"},{"number":1062,"title":"BigNumber precision divergence in `_afterIsolatedCollateralFullWithdraw` can permanently block isolated collateral withdrawals","author":"0xrox"},{"number":1065,"title":"Interest Accumulation During Protocol Pause Causes Unfair Liquidations","author":"0xh4153c"},{"number":1067,"title":"Full Liquidation Lacks Maximum Payback Protection, Exposing Liquidators to Exchange Rate Drift","author":"ExtraCaterpillar"},{"number":1069,"title":"Small Normal Borrow Positions Cannot Be Liquidated Due to `_verifyAmountLimits` Lower Bound","author":"ExtraCaterpillar"},{"number":1070,"title":"Protocol Fees Accrued During Swap Are Not Claimable or Withdrawable","author":"ExtraCaterpillar"},{"number":1071,"title":"Global cap \u201cphantom usage\u201d via ROUND_UP on decreases enables permanent cap locking","author":"0x23r0"},{"number":1073,"title":"Swap Functions Lack Deadline Parameter, Allowing MEV Timing Exploitation","author":"ExtraCaterpillar"},{"number":1074,"title":"No-admin Liquidity cash shortfall mints stored credit to arbitrary to_, enabling theft of unrelated future inflows from DexV2 balance","author":"nitinaimshigh"},{"number":1077,"title":"MoneyMarket can underflow BigMath-rounded debt totals, permanently preventing full repayment (and liquidations) for some multi-position debts","author":"Diavolo"},{"number":1079,"title":"`settle()` can spend tokens backing other users\u2019 stored balances","author":"0x23r0"},{"number":1082,"title":"Users can block liquidation temporary via repaying dust borrow positions","author":"0x37"},{"number":1083,"title":"M-01: Oracle-Pool sqrtPrice Divergence Destroys D3/D4 Liquidation Incentive","author":"timefliez"},{"number":1084,"title":"Chainlink oracle read lacks sign/staleness validation, enabling mispricing over-borrow and critical-path DoS","author":"BroRUok"},{"number":1085,"title":"Oracle-Derived Valuation of D3/D4 Positions Ignores Actual DEX Pool State causes Ghost Collateral","author":"0xh4153c"},{"number":1086,"title":"Lack of deadline when performing a swap","author":"EddiePumpin"},{"number":1088,"title":"Arbitrary reduction of dynamic fee protection via reverse cleansing trades","author":"Shalala"},{"number":1089,"title":"MoneyMarket: D3 HF uses oracle-implied LP composition, blocking liquidation when pool-price composition is unsafe","author":"Edoscoba"},{"number":1090,"title":"DexV2 (D3): `feeVersion==1` swaps can be permanently DoSed when price sits in a zero-liquidity gap (stale `zeroPriceImpactPriceX96` baseline \u21d2 `PriceImpactTooHigh`)","author":"Edoscoba"},{"number":1092,"title":"DexV2 may fail to refund native Ether to users","author":"0x37"},{"number":1095,"title":"DexV2 settle() can force SKIP_TRANSFERS , allowing any user to inflate Liquidity utilization/borrow rate with zero transfers","author":"BroRUok"},{"number":1099,"title":"Borrowed asset will be permanently stuck in the DEX contract","author":"air_0x"},{"number":1100,"title":"Dynamic-Fee \u201cDecay Time\u201d Can Round To Zero And Reset Fees Within The Same Block (LP Fee Bypass)","author":"Edoscoba"},{"number":1101,"title":"Users Can Block D3/D4 Liquidations by Withdrawing Fees, Causing Protocol Bad Debt","author":"0xh4153c"},{"number":1102,"title":"D4 smart debt positions that go out of range cannot be repaid through payback(), leaving borrowers unable to close their position","author":"shieldrey"},{"number":1104,"title":"Liquidation DoS: `_calculateSqrtPriceX96()` can overflow and revert, bricking `getHfInfo(..., false)` and `liquidate()`","author":"Edoscoba"},{"number":1106,"title":"Money Market: `paybackAll` can overpay in raw units and trigger `Panic(0x11)`, blocking full repayment","author":"Edoscoba"},{"number":1107,"title":"Swap Functions Lack Deadline Protection","author":"PowPowPow"},{"number":1108,"title":"Accounting Bypass via settle creates Ghost Balances leading to Fund Theft","author":"fuzious"},{"number":1109,"title":"Protocol Fee Revenue Is Permanently Locked in D3/D4 Pools With No Collection Mechanism","author":"Harry-Elite"},{"number":1117,"title":"Position Deletion Front-Running in Liquidations","author":"alicrali33"},{"number":1118,"title":"Liquidation and HF computation can revert for NFTs with D3/D4 positions due to Q192 overflow in `_calculateSqrtPriceX96`","author":"xiaoming90"},{"number":1119,"title":"Unintended Fee Minimization Due to Dynamic Fee State Reset","author":"BensonDynasty"},{"number":1120,"title":"Single-D4 position forces `paybackPositionIndex == withdrawPositionIndex`, causing liquidation revert (DoS)","author":"Blackdruid"},{"number":1122,"title":"CollateralFactor=0 underflow in `_calculateCollateralValues` bricks operate-mode HF checks and can lock user positions","author":"xiaoming90"},{"number":1123,"title":"Best-effort controller dynamic-fee callback can be forced to fail, bypassing fee overrides and enabling selective fee manipulation","author":"xiaoming90"},{"number":1124,"title":"MaxUtilization Enforcement Bypassed via DexV2 Fast-Path Settle Deferred Borrow Accounting","author":"nitinaimshigh"},{"number":1125,"title":"Approved Spenders Cannot Modify Existing Positions","author":"pashap9990"},{"number":1127,"title":"Users can lose withdrawn tokens to the MoneyMarket contract","author":"0xnija"},{"number":1128,"title":"Tick-griefing via tickSpacing = 1 can brick DexV2 swaps through gas/OOG","author":"xiaoming90"},{"number":1129,"title":"`SupplyExchangePrice` Inflation Could lead to Swap Denial-of-Service","author":"BensonDynasty"},{"number":1130,"title":"Exchange Prices Baked into `sqrtPriceX96` when Calculating Health Factor.","author":"Audinarey"},{"number":1134,"title":"MoneyMarket off-by-one rounding desyncs raw debt vs Liquidity, making borrows impossible to fully repay and liquidations revert","author":"xiaoming90"},{"number":1135,"title":"Rounding drift between MoneyMarket and Liquidity can make normal borrow positions impossible to fully close","author":"xiaoming90"},{"number":1140,"title":"Global operation flag + global PendingTransfers counts enable reentrancy-based PT poisoning to revert (or brick) all DexV2 operations","author":"xiaoming90"},{"number":1141,"title":"Controller dynamic-fee return decoding is not revert-contained, allowing swap DoS via malformed \u201csuccessful\u201d returndata","author":"xiaoming90"},{"number":1142,"title":"Controller dynamic-fee hook can still brick swaps via return-data bomb despite 200k gas cap","author":"xiaoming90"},{"number":1143,"title":"Dynamic Fee Decay Can Be Manipulated via Zero Impact Swaps","author":"BensonDynasty"},{"number":1145,"title":"The protocol will underpay D3 LPs their fee yield","author":"fuzious"},{"number":1147,"title":"Hard-coded oracle price bounds can brick health factor computation, freezing withdrawals/borrows and preventing liquidations","author":"xiaoming90"},{"number":1149,"title":"Exact-output swaps can be DoSed by dust liquidity causing zero-output steps in `_swapOut`","author":"xiaoming90"},{"number":1151,"title":"Phantom fee rounding in `swapOut` charges tokenIn on zero-input steps, overcharging users and stranding fees","author":"xiaoming90"},{"number":1152,"title":"swapOut dynamic-fee gross-up charges phantom tokenIn on zero-input steps, enabling cumulative user loss and unclaimable fee reserves","author":"xiaoming90"},{"number":1153,"title":"`_removeLiquidity` can revert on extreme desired amounts before capping to position liquidity, breaking unwind and liquidation flows","author":"xiaoming90"},{"number":1154,"title":"Stale `dexVariables2` writeback after external controller call can clobber concurrent updates.","author":"Rizalfahmi"},{"number":1155,"title":"Payback rounding-to-zero lets borrowers reduce debt without repaying","author":"xiaoming90"},{"number":1157,"title":"Permissionless D3/D4 default caps can be multiplied across DexKey variants","author":"xiaoming90"},{"number":1160,"title":"Swap Direction Flip due to `sqrtPrice` Rounding","author":"BensonDynasty"},{"number":1161,"title":"User ETH can get stuck in the DEX on a failed settle","author":"0xnija"},{"number":1163,"title":"D4 debt rounding-to-zero can make Health Factor treat non-zero debt as zero, bypassing collateral checks and creating bad debt","author":"xiaoming90"},{"number":1164,"title":"Dynamic-fee controller can bypass the \u201cnon-blocking hook\u201d design and DoS swaps by poisoning global PendingTransfers","author":"xiaoming90"},{"number":1165,"title":"Rounding Asymmetries in Fluid Money Market Leading to Unfair Liquidations","author":"0xBug_X"},{"number":1168,"title":"D4 fees are not double counted in health factor checks","author":"0xnija"},{"number":1172,"title":"DexV2 rebalance cannot use Liquidity netting, making `_unaccountedBorrowAmount` permanently uncleared and desyncing fees and payouts","author":"xiaoming90"},{"number":1173,"title":"MoneyMarket payback raw rounding mismatch can desync debt from Liquidity, enabling repeated high-value liquidations and permanent phantom debt","author":"xiaoming90"},{"number":1174,"title":"Pool controller can bypass external dynamic-fee fetching to evade LP fee overrides","author":"xiaoming90"},{"number":1176,"title":"Dead-end eMode configuration prevents resetting token CF/LP back to NO_EMODE","author":"xiaoming90"},{"number":1179,"title":"Minimum-amount enforcement on close-out paths strands sub-minimum dust and can lock meaningful value per position","author":"xiaoming90"},{"number":1180,"title":"BigMath ROUND_UP drift can underflow `_updateStorageForPayback`, permanently bricking repay and liquidation payback","author":"xiaoming90"},{"number":1181,"title":"BigMath ROUND_UP drift can underflow `_afterIsolatedCollateralFullWithdraw`, permanently blocking isolated collateral exit and related cleanup","author":"xiaoming90"},{"number":1184,"title":"Debt accounting mismatch makes payback-all overpay Liquidity and strands unrecoverable dust, permanently locking collateral","author":"xiaoming90"},{"number":1186,"title":"Fee-stored liquidation can underpay beyond the $0.01 dust tolerance due to biased rounding and unconditional `withdrawValue_ = 0`","author":"xiaoming90"},{"number":1187,"title":"BigMath ROUND_UP no-op payback can strand unpayable debt dust and permanently lock minimum collateral","author":"xiaoming90"},{"number":1188,"title":"Difference between pool price and oracle price can lead to wrongful liquidations","author":"dandan"},{"number":1189,"title":"Liquidity pause semantics are inconsistent, allowing D3/D4 liquidations during pause while DoS\u2019ing normal liquidations","author":"xiaoming90"},{"number":1190,"title":"Equity-based liquidation-penalty cap sets liquidation bonus to 0 for underwater positions, stalling liquidations and creating bad debt","author":"xiaoming90"},{"number":1191,"title":"Liquidation penalty cap can make liquidations fail to restore health factor, leaving persistent liquidatable debt and bad debt","author":"xiaoming90"},{"number":1192,"title":"Withdraw-all sentinel rounds down withdrawal tokens but deletes the full raw supply position, causing supplier underpayment","author":"xiaoming90"},{"number":1193,"title":"Missing checks when removing liquidity allows initializing ticks with dust","author":"dandan"},{"number":1195,"title":"Missing cross-token decimals normalization in `_calculateSqrtPriceX96`","author":"oct0pwn"},{"number":1198,"title":"Gas Griefing via Position Saturation causes Liquidation DoS","author":"fuzious"},{"number":1199,"title":"A swapper will permanently DoS swaps (and potentially LP withdrawals) for pool users","author":"jo13"},{"number":1200,"title":"`_beforeCreatingIsolatedCollateralPosition` Can block Isolated Collateral Borrowing.","author":"Audinarey"},{"number":1201,"title":"Systemic Excessive Precision Loss in Swap Modules Leads to 100% Value Leak for Small Amounts.","author":"Peter3144"},{"number":1203,"title":"Attacker will cause double withdraw/borrow and cap or health-factor bypass for D3/D4 users and the protocol by reentering DEX_V2.operate() from token hooks during settle","author":"Tupaia"},{"number":1204,"title":"D3/D4 position cap \"current\" desynchronization causes underflow on all withdraw/payback paths, permanently trapping funds","author":"Tupaia"},{"number":1205,"title":"Malicious or faulty oracle will cause incorrect liquidations and bad debt for vault users as the protocol will accept prices in [1, 1e54]","author":"srlock"},{"number":1208,"title":"Admin will cause permanent loss of protocol control for governance and users as a single mistaken or malicious setAdmin() call will transfer admin without confirmation","author":"srlock"},{"number":1210,"title":"`Vault factory owner will cause full compromise of factory and user funds for the protocol and deployers as spell() will execute arbitrary code in factory context via delegatecall`","author":"srlock"},{"number":1211,"title":"Wrong calculation in conversion of normal number to big number with rounding-up","author":"Tupaia"},{"number":1212,"title":"Denial of service in dynamic fee calculation when time elapsed exceeds decay time remaining","author":"Tupaia"},{"number":1213,"title":"`Governance will cause immediate loss of funds or control for DEX users and LPs as upgradeTo() will change implementation with no timelock`","author":"srlock"},{"number":1215,"title":"FluidMoneyMarketOperateModule will mint positions to msg.sender instead of the specified to address","author":"shiazinho"},{"number":1217,"title":"`MEV bots will cause value extraction and worse execution for LPs and users as the protocol will apply predictable asymmetric rounding to sqrtPriceX96`","author":"srlock"},{"number":1218,"title":"ERC721 implementation violates EIP's MUST","author":"lodelux"},{"number":1219,"title":"D3 fee accrual amounts are treated as assets without applying the supply exchange price","author":"zubyoz"},{"number":1221,"title":"`Liquidity governance compromise will cause full DEX governance takeover for DEX users and LPs as DEX V2 will read governance from Liquidity storage`","author":"srlock"},{"number":1222,"title":"Malicious Router Stored Credit Manufacturing and Rebalance DoS","author":"oct0pwn"},{"number":1223,"title":"`Protocol fee logic will cause full loss of swap output for users as very small swaps can have output reduced to zero without revert`","author":"srlock"},{"number":1224,"title":"`MEV bots will capture liquidation incentives and worsen execution for liquidators and vault users as liquidation has no priority ordering or delay`","author":"srlock"},{"number":1226,"title":"`Attacker with flash loans will cause price or oracle manipulation and arbitrage losses for LPs and protocol as there are no size or TWAP safeguards`","author":"srlock"},{"number":1228,"title":"OOG revert if Governance wants to list an eMode with many tokens overrides","author":"lodelux"},{"number":1230,"title":"Dynamic Fee calculated in `helpers::_calculateStepDynamicFee` Is Not Explicitly Bounded by Min Fee and Max Fee","author":"Spomaria"},{"number":1231,"title":"Disproportionate Fee Extraction via Temporary Liquidity Inflation","author":"0xxAristos"},{"number":1233,"title":"Missing Permission Check for `COLLATERAL_CLASS_PERMISSIONED` in Normal Supply Positions","author":"Audinarey"},{"number":1236,"title":"Dynamic-fee baseline stays anchored to pre-traversal price when swap starts with zero active liquidity, causing (A) max-fee overcharging + netPriceImpact corruption and (B) deterministic swap reverts (`PriceImpactTooHigh`) for large empty gaps","author":"thimthor"},{"number":1238,"title":"Attacker will execute a write-reentrancy through `operate()` during `dexCallback` in `settle()`, accumulating unsettled pending amounts that permanently DoS the caller's session","author":"felconsec"},{"number":1240,"title":"D4 Quadratic Solver Reverts on Large Debt Amounts - Liquidation DoS","author":"charm1987"},{"number":1241,"title":"Uncapped computation of time elapsed when calculating exchange prices results in DoS","author":"WillyCode20"},{"number":1242,"title":"Permanent Storage Corruption & Security Bypass via Exponent Bit-Leakage in BigMathUnsafe","author":"ArkheionX"},{"number":1245,"title":"Missing Transaction Deadline Protection in Swap and Liquidity Functions","author":"TECHFUND-inc"},{"number":1246,"title":"High-Supply Token Imbalance Overflow Causes DoS on Smart Debt Positions","author":"sach1r0"},{"number":1247,"title":"FeeVersion==1 Swap Liveness DoS When Starting From Zero Active Liquidity","author":"AV"},{"number":1248,"title":"Missing non-zero validation on calculated denominators \u2192 deterministic DoS of swapIn / swapOut (Medium)","author":"InvisibleKTweb3"},{"number":1249,"title":"Improper Runtime State Reset in Dynamic Fee Update Enables MEV Backrunning","author":"WillyCode20"},{"number":1250,"title":"Liquidation Callback Skips Amount Limits, Amplifying Downstream Math Risks","author":"charm1987"},{"number":1251,"title":"Users Can Be Prematurely Liquidated","author":"Audinarey"},{"number":1252,"title":"Same-Block Price Manipulation Vulnerability in Liquidity Removal Calculations","author":"TECHFUND-inc"},{"number":1253,"title":"Sticky Caps Grant Unauthorized Borrowing on Restricted Assets","author":"sach1r0"},{"number":1255,"title":"Net-transfer-out settle does not revert, report claim is a non-issue","author":"0xnija"},{"number":1256,"title":"Users can pull tokens out during a deposit and it looks like a drain","author":"0xnija"},{"number":1257,"title":"Resetting `decayTimeRemaining` to zero during zero-impact swap allows for exploition","author":"WillyCode20"},{"number":1258,"title":"Borrowers will be unable to use D4 pools at low tick ranges due to division by zero and integer overflow","author":"Leaningone"},{"number":1260,"title":"Decimal-Agnostic Amount Limits Create Unfair Economic Barriers and DOS Vectors","author":"Cybrid"},{"number":1261,"title":"PendingTransfers Counter Underflow via Unchecked Assembly Subtraction","author":"charm1987"},{"number":1263,"title":"DexV2 Failure Swallowing Bypasses Liquidity Layer Pause and Limits","author":"fuzious"},{"number":1264,"title":"Tick and sqrtPrice Rounding Exploits","author":"neme"},{"number":1265,"title":"Lack of Cross-Pool Reentrancy lock allows liquidity draining across pools using Flash Loan price manipulation","author":"TECHFUND-inc"},{"number":1266,"title":"Tolerance Enforcement in `main::operate` Is Incorrectly Applied and Can Allow Up to ~11\u00d7 Deviation","author":"Spomaria"},{"number":1269,"title":"Pending Transfer Invariant Violation via Liquidity Layer Failure","author":"Frontrunner"},{"number":1270,"title":"D3 Position Liquidation DOS via Fee Exhaustion","author":"folip"},{"number":1271,"title":"D3 withdraw() Removes Input Validation","author":"charm1987"},{"number":1272,"title":"Dynamic Fee Reset MEV Risk","author":"neme"},{"number":1274,"title":"D4 Borrow Allows Deferred Redemption That Bypasses Liquidity Borrow Caps","author":"nitinaimshigh"},{"number":1275,"title":"MEV Bots will extract value from protocol and LPs as Controller will clear dynamic fee runtime state","author":"droopyman12"},{"number":1277,"title":"settle() dexCallback Enables Write-Reentrancy Into operate()","author":"charm1987"},{"number":1280,"title":"Attacker will drain protocol funds via phantom `_userStoredTokenAmount` credit when liquidity layer call fails","author":"ZeroTrust"},{"number":1282,"title":"User will permanently lose ETH when native token `settle()` falls back due to Liquidity layer revert","author":"ZeroTrust"},{"number":1284,"title":"Transient Fee Reset Enables Predictable MEV Window","author":"iceprince8175"},{"number":1285,"title":"In certain cases fees offsetting can hurt borrowers","author":"PASCAL"},{"number":1286,"title":"`decrementPendingSupplyCount()` / `decrementPendingBorrowCount()` Use Unchecked Assembly `sub`, Permanently Bricking Session Finalization When Count Invariant Is Broken by Write-Reentrancy","author":"felconsec"},{"number":1288,"title":"Liquidator will over-seize borrower collateral without reducing borrower debt","author":"axelot"},{"number":1289,"title":"Liquidation DoS via Front-Running Position Shifts","author":"fuzious"},{"number":1290,"title":"# Swaps will revert indefinitely as uncapped elapsed time inflates exchange prices beyond usable bounds","author":"droopyman12"},{"number":1292,"title":"While adding and deploying liquidity the execution can get failed.","author":"nikhil840096"},{"number":1295,"title":"# Swaps calculate incorrect token amounts as sqrt price correction flips swap direction","author":"droopyman12"},{"number":1296,"title":"Swap Direction Inconsistency Due to sqrtPrice Rounding Correction","author":"WillyCode20"},{"number":1297,"title":"Dynamic-fee `priceImpactToFeeDivisionFactor` allows zero, causing division-by-zero swap DoS (controller misconfiguration footgun)","author":"Blackdruid"},{"number":1299,"title":"Auths can steal all user funds","author":"Protokol"},{"number":1300,"title":"[M-2] Partial Liquidation Bypasses `minNormalizedCollateralValue` Invariant, Systematically Creating Zombie Positions That Accumulate Protocol Bad Debt","author":"CryptoGuardian"},{"number":1301,"title":"Borrower can be permanently unable to fully close their isolated borrow position, affecting last borrowers in an isolated cap group","author":"axelot"},{"number":1302,"title":"Deposit function uses fixed raw 10000 minimum before decimals adjustment leading to inconsistent dust protection and inconsistence shares accouning","author":"oluwaseyisekoni"},{"number":1303,"title":"# MEV bots will extract protocol revenue as dust swaps exploit precision loss to instantly reset dynamic fee decay","author":"droopyman12"},{"number":1304,"title":"Borrower will silently receive ~51% less value than requested when borrowing at the lower price boundary","author":"rth"},{"number":1305,"title":"MoneyMarket D3 Withdraw Does Not Revert on Liquidity Risk-Control Failure; DexV2 Mints \u201cStored Credit\u201d (IOU), Undermining Withdrawal Limits and Enabling Front\u2011Running of Future Inflows","author":"BroRUok"},{"number":1306,"title":"Time-Accumulation Inflation of SupplyExchangePrice Causing Swap DoS","author":"iceprince8175"},{"number":1308,"title":"User funds can be drained through malicious controller","author":"EddiePumpin"},{"number":1309,"title":"Public docs specify wrong creation sentinels for operate(), breaking integrations","author":"nitinaimshigh"},{"number":1311,"title":"Attacker will permanently block liquidation of their position causing bad debt accumulation for the protocol","author":"Tenalia-Audits"},{"number":1312,"title":"Unprotected zero fee window in permissionless DEX nitialization","author":"Shalala"},{"number":1314,"title":"Interest-Free Borrowing via `_unaccountedBorrowAmount` When Liquidity Layer Is Bypassed","author":"velev"},{"number":1317,"title":"Users' fees may be locked in the Low-Volume Liquidity Pools","author":"0x37"},{"number":1318,"title":"stored  funds from failed liquidity layer call will be unrecoverable during full withdrawal","author":"air_0x"},{"number":1320,"title":"DOS through division by 0","author":"EddiePumpin"},{"number":1323,"title":"Atomic State Incoherence via Stored sqrtPriceX96 Enables Read-Only Reentrancy Liquidation Exploit in Money Market","author":"The_Last_Gladiator"},{"number":1325,"title":"MoneyMarket D3 Position Cap Usage Drifts Upward After Add\u2192Remove Round Trip","author":"Edoscoba"},{"number":1326,"title":"Systematic rounding up can cause position\u2013cap accounting mismatch leading to permanent DoS","author":"touristS"},{"number":1327,"title":"Dust\u00a0position creation in liquidation module due to rounding error when paying back full debt","author":"touristS"},{"number":1328,"title":"Liquidity providers can control dynamic fee system by withdrawing liquidity to prevent fee decay updates","author":"touristS"},{"number":1330,"title":"Traders can pay minimum fees on large swaps by resetting fee pressure cheaply","author":"axelot"},{"number":1331,"title":"DexV2 settle can mint redeemable stored credit on Liquidity failure","author":"BradMoonUESTC"},{"number":1333,"title":"Third party relays/recipients will lose mis-routed funds","author":"bugbear"},{"number":1334,"title":"Initial deployer of liquidity can harm the protocol and the pool.","author":"nikhil840096"},{"number":1335,"title":"DexV2 settle can manipulate Liquidity utilization and rates without transfers","author":"BradMoonUESTC"},{"number":1336,"title":"Reduced Interest Payouts from D4 Borrowers Altering Liquidity Composition","author":"0xxAristos"},{"number":1337,"title":"Isolated-collateral full withdraw can brick due to underflow","author":"0xShoonya"},{"number":1338,"title":"MoneyMarket withdraw and borrow limits can be bypassed via DexV2 stored credit when Liquidity reverts","author":"BradMoonUESTC"},{"number":1339,"title":"D4 Position Caps Are Overly Restrictive \u2014 Users Cannot Borrow Up to the Admin-Configured Debt Limit","author":"gabkov"},{"number":1340,"title":"Fail-Open Controller Dynamic-Fee Fetch Allows 0 LP-Fee Swaps","author":"Edoscoba"},{"number":1341,"title":"Hard dependency on fee storage in D3/D4 liquidation logic leads to griefable liquidation failures and bad debt accumulation","author":"makeWeb3safe"},{"number":1342,"title":"A user can escape swap fee through liquidation","author":"EddiePumpin"},{"number":1343,"title":"Tick / sqrtPrice Rounding Edge Causes Swap-Step Direction Flip","author":"iceprince8175"},{"number":1344,"title":"MoneyMarket D4 Borrow Does Not Revert on Liquidity Risk-Control Failure; DexV2 Mints Redeemable \u201cStored Credit\u201d (IOU) That Bypasses Borrow Limits and Utilization Constraints","author":"BroRUok"},{"number":1345,"title":"Global liquidity desynchronization via silent tick crossing","author":"Shalala"},{"number":1346,"title":"Loss incurred by liquidators due to rounding is excess","author":"lanrebayode77"},{"number":1347,"title":"Truncattion of SqrtPriceX96 would lead to mismatch between balance and expected balance","author":"silver_eth"},{"number":1348,"title":"Users can reduce the fees they are required to payback","author":"theweb3mechanic"},{"number":1349,"title":"Dust Debt Below `FOUR_DECIMALS` Becomes Permanently Uncleared \u2014 Cannot Repay, Cannot Liquidate","author":"velev"},{"number":1351,"title":"Dominant LP can inflate dynamic LP fees by temporarily reducing liquidity","author":"0xPhantom2"},{"number":1352,"title":"Non-whitelisted user is able to borrow/repay on D4 pools via swaps","author":"bugbear"},{"number":1353,"title":"An attacker will bypass tick-crossing state updates for LPs and traders.","author":"slAGeR"},{"number":1355,"title":"_addLiquidity doesnt roundUp rawAmounts","author":"silver_eth"},{"number":1359,"title":"liquidator can seize collateral while the borrower's MoneyMarket debt remains unchanged","author":"MohammadX2049"},{"number":1361,"title":"Unchecked addition into packed `activeLiquidity` (X102)","author":"hexcoded0033"},{"number":1363,"title":"A liquidity provider can DoS D4 liquidation paths for lenders","author":"axelot"},{"number":1364,"title":"Liquidator cannot liquidate fee-only positions when combined fees cover withdraw value up to dust threshold","author":"Tenalia-Audits"},{"number":1365,"title":"An attacker will claim fees multiple times from LP fee accounting.","author":"slAGeR"},{"number":1366,"title":"Protocol doesnt enforce that isolated collateral is isolated","author":"silver_eth"},{"number":1367,"title":"DOS of normal borrow position","author":"EddiePumpin"},{"number":1368,"title":"`MoneyMarket` callback will render ETH Smart Collateral/Debt inoperable for the protocol and its users.","author":"amkdev"},{"number":1369,"title":"DexV2 settle() Can Mint Redeemable Stored Credit Under a netAmount == 0 Parameterization When Liquidity Fails, Enabling Front\u2011Running / Draining of Future Inflows","author":"BroRUok"},{"number":1371,"title":"State-Not-Cleared Reentrancy (caused by a violation of the CEI pattern) and Missing Access Control in a core callback function.","author":"songyuqi"},{"number":1373,"title":"Msg.Value Loss in Cross-Contract Callbacks Leads to Stuck User Funds During D3/D4 Native Token Operations","author":"la-arana-inteligente"},{"number":1375,"title":"Malicious User will corrupt internal accounting and cause fund loss for Liquidity Providers","author":"nnoy"},{"number":1377,"title":"Users will cause bad debt for the protocol due to incorrect rounding direction in D4 debt creation","author":"nnoy"},{"number":1378,"title":"Users will cause guaranteed bad debt for the protocol due to incorrect rounding and explicit debt reduction in borrow","author":"nnoy"},{"number":1379,"title":"Incorrect rounding direction and explicit deduction in fee calculations will leak revenue from the protocol","author":"nnoy"},{"number":1380,"title":"Logic error in `_liquidate` will cause excessive collateral seizure for the user","author":"nnoy"},{"number":1381,"title":"Missing slippage validation in `_liquidate` will cause uncontrolled financial loss for liquidators","author":"nnoy"},{"number":1382,"title":"Arithmetic underflow in BigMathVault.mulDivNormal will incorrectly return zero for protocol accounting","author":"nnoy"},{"number":1383,"title":"Malicious User will cause Protocol Insolvency for Fluid Protocol","author":"nnoy"},{"number":1384,"title":"Arbitrary price cap in `_liquidate` will cause unfair over-seizure of collateral for users during high price volatility","author":"nnoy"},{"number":1385,"title":"Missing validation for explicitly disallowed token decimals in `AdminModule` will cause protocol specification violation","author":"nnoy"},{"number":1386,"title":"Whitelisted D4 user will DoS borrow/payback/liquidation for D4 position users","author":"connectouch"},{"number":1387,"title":"Cross-Contract Liquidity State Desynchronization Between Liquidity, Dex, and Money Market Logic","author":"RoushanGoswami"},{"number":1388,"title":"D4: `payback()` burns debt-position liquidity while charging 0 repayment (rounding-to-zero)","author":"Edoscoba"},{"number":1389,"title":"All-or-nothing `rebalance()` can revert on Liquidity\u2019s per-call ratio guard once `_unaccountedBorrowAmount` crosses `2**80`, causing token-specific liveness outages and delayed settlements","author":"xiaoming90"},{"number":1392,"title":"Dynamic-Fee Decay Resettable by Zero-Impact Swaps","author":"iceprince8175"},{"number":1393,"title":"Dynamic Fee Invariant Failure in High Minimum Fee Regimes (Floor Clipping)","author":"proofvoid"},{"number":1394,"title":"An attacker can create unfunded stored credit balances, affecting all DexV2 users and the Money Market","author":"axelot"},{"number":1395,"title":"Arbitrageurs will reduce fee payments for LPs and the protocol","author":"silver_eth"},{"number":1396,"title":"Users can capture fees on d4 positions by resupplying borrowed amounts","author":"silver_eth"},{"number":270,"title":"Protocol Fee Is Charged on the LP-Fee-Inclusive Amount (Fee-on-Fee), Increasing Effective Swap Fees","author":"heavyw8t"},{"number":1322,"title":"Liquidator can seize riskier collateral at below-configured penalty rates, under-penalizing riskier tokens","author":"axelot"},{"number":942,"title":"Any user will have exact stored-withdrawal locked despite sufficient DEX-side liquidity","author":"neeloy"},{"number":1370,"title":"permissionless D3 token onboarding fails for unlisted tokens due to mandatory Liquidity exchange-price dependency","author":"MohammadX2049"},{"number":427,"title":"Counter Pending Transfers are Global, Not Per-User, Which Will Result in False Reverts and Coupling Between Users","author":"JuggerNaut"},{"number":287,"title":"jdhart81 - Aggressive Fee Rounding Causes User Value Loss on Small Swaps","author":"Viridis"},{"number":1372,"title":"Lp can charge more fees","author":"veerendravamshi"},{"number":209,"title":"Health Factor Calculation Enables Liquidation DoS and Bad Debt Accumulation","author":"gabkov"},{"number":247,"title":"Incorrect signed tick compression causes invalid bitmap traversal for negative ticks, leading to skipped or incorrect initialized ticks","author":"attacker_code"},{"number":45,"title":"Cross-Pool Operation Injection via Unbound `operate()` Enables Stale Price Exploitation Affecting $5.1B Liquidity Layer","author":"0x_oi"},{"number":504,"title":"jdhart81 - D2 `_swapOut` Uses Uninitialized `amountIn_` in Reserve Verification, Weakening Minimum Liquidity Safety Check","author":"Viridis"},{"number":939,"title":"Competing liquidations cause incorrect withdrawal from moved position after deletion","author":"Tupaia"},{"number":1148,"title":"D4 whitelist can be bypassed because MoneyMarket is the whitelisted caller","author":"0xnija"},{"number":496,"title":"Liquidation of D4 (smart debt) positions only seizes fee-stored amounts, not the actual debt position, allowing undercollateralized positions to persist","author":"navie1230"},{"number":354,"title":"Attacker can create multiple small positions to avoid liquidation","author":"SOPROBRO"},{"number":1038,"title":"D3: Permissionless swapIn/swapOut extract value when supply EPs diverge","author":"hirusha"},{"number":1171,"title":"Minimum fee-collection amount check strands fee dust and blocks D3/D4 position deletion","author":"xiaoming90"},{"number":1146,"title":"15-bit timestamp wrap lets attackers freeze dynamic-fee decay, enabling fee underpayment, fee griefing, and swap DoS","author":"xiaoming90"},{"number":826,"title":"Isolated Collateral Cap Griefing via Disproportionate Debt Accounting","author":"0xRstStn"},{"number":1056,"title":"Liquidation eligibility and post-conditions for D3/D4 positions can be wrong because HF decomposes positions using an oracle-implied `sqrtPriceX96` while liquidation uses the pool `sqrtPriceX96`.","author":"auditbase"},{"number":913,"title":"Permanent DoS of rebalance Functions due to Precision Mismatch between nativeTokenAllowances and BigMathMinified","author":"gelenbedalen"},{"number":1156,"title":"Fee realization is not reflected in per-pool `_tokenReserves`","author":"xiaoming90"},{"number":2,"title":"Inconsistent Oracle pricing context for D4 fee valuation leads to liquidation discrepancies","author":"Aziz0033"},{"number":1139,"title":"Zero-raw liquidation payback lets liquidators seize collateral without reducing borrower debt","author":"xiaoming90"},{"number":540,"title":"Crossing `MIN_TICK` writes an unencodable tick, bricking the pool","author":"nisedo"},{"number":497,"title":"Position cap underflow in `_updatePositionCapsForD3D4LiquidityDecrease` permanently bricks all new deposits to the affected DEX pool","author":"navie1230"},{"number":1329,"title":"Reentrancy allows collateral drain after NFT transfer","author":"ff4de"},{"number":710,"title":"Missing liquidity layer borrow rate limit check can cause permanent rebalance() DoS","author":"luc1jan"},{"number":1136,"title":"Liquidation seizes D3 collateral with `amount0Min/amount1Min = 0`, forcing liquidators to accept unbounded token-composition risk and degrading liquidation liveness","author":"xiaoming90"},{"number":1002,"title":"# Unwhitelisted users will execute D3 deposit/withdraw despite allowlisting for protocol operators","author":"felconsec"},{"number":1207,"title":"Attacker can deteriorate a position's health factor using liquidation","author":"0xgritty"},{"number":1137,"title":"Phantom `_unaccountedBorrowAmount` updates on Liquidity failure can permanently DoS `rebalance()` and strand user IOUs","author":"xiaoming90"},{"number":11,"title":"Tick Overflow at MIN_TICK Boundary Corrupts Pool State","author":"taronsung"},{"number":38,"title":"15-bit Timestamp Wrap-around Breaks Dynamic Fee Decay in Long-inactive Smart Debt Pools","author":"I1iveF0rTh1Sh1t"},{"number":50,"title":"Wrong Exchange Price Used in D1/D2 Swap Accounting Corrupts Pool State","author":"Mr.BlackKeys"},{"number":57,"title":"MIN_TICK Boundary Overflow Corrupts Pool Tick State to Zero","author":"codecoffeeguy"},{"number":64,"title":"DEX Pool Operator will corrupt pool state and steal LP funds through tick truncation due to insufficient bit allocation","author":"TradingViews"},{"number":83,"title":"Asymmetric rounding in D3/D4 cap accounting causes permanent cap-utilization drift, eventually DoSing new deposits","author":"coinsspor"},{"number":87,"title":"DOS in `DexV2AdminModule.rebalance(NATIVE_TOKEN)` due to incorrect `msg.value` calculation causes permanent failure to sync native unaccounted borrows","author":"0xastronatey"},{"number":93,"title":"Protocol will steal funds from LPs as protocol cut calculation can exceed LP fee amount","author":"Daian0s"},{"number":99,"title":"Liquidation index shift lets liquidators seize unintended collateral","author":"0xb0k0"},{"number":112,"title":"`_getHfInfo()` uses oracle-implied sqrtPrice for D3/D4 amounts instead of DexV2 pool price enabling undercollateralized borrowing and unliquidatable bad debt","author":"Silvermist"},{"number":134,"title":"Liquidation (NORMAL_BORROW): biased payback raw conversion causes MoneyMarket to under-book debt vs Liquidity, enabling collateral seizure for uncredited raw reduction (0 in boundary case)","author":"Baazigar"},{"number":135,"title":"Liquidator will bypass access controls and corrupt state for NFT position holders via index collision","author":"luckyidiot"},{"number":146,"title":"Fee Calculation Order Inconsistency Creates Arbitrage Opportunity","author":"Greedy_Biggie"},{"number":153,"title":"Attacker will steal all pool funds by exploiting unchecked arithmetic overflow in D4 swap calculations","author":"Yakecho"},{"number":160,"title":"Protocol will artificially reduce available capacity for all users by systematically over-counting token usage through incorrect rounding direction in withdraw/payback operations","author":"luckyidiot"},{"number":170,"title":"Incorrect Fee Pricing due to 15-bit Timestamp Wrap-Around Blind Spot","author":"luckyidiot"},{"number":180,"title":"NFT Ownership Hijacking via Reentrancy in operate()","author":"coinsspor"},{"number":185,"title":"An attacker will cause bad debt for the protocol and LPs","author":"0xUnderflow"},{"number":195,"title":"Asymmetric fee structure causes loss of protocol/LP fee, and causes worse exchangeRate and greater price slippage to user","author":"0xCrypt0nite"},{"number":197,"title":"Liquidate: Wrong collateral seized when `paybackPositionIndex == withdrawPositionIndex` and payback deletes the position","author":"uba"},{"number":203,"title":"# Fee Calculation Order Inconsistency Causes LP Revenue Leakage in SwapIn Operations","author":"dieworu"},{"number":232,"title":"D3/D4 Callback Stale nftConfig Overwrites NFT Ownership","author":"coinsspor"},{"number":260,"title":"Users will lose funds through unvalidated exchange price manipulation in extreme market conditions","author":"ChefJay"},{"number":276,"title":"D3 whitelist bypass allows unauthorized deposits, withdrawals, and swaps during permissioned launch","author":"0xb0k0"},{"number":285,"title":"jdhart81 - 15-bit Timestamp Compression Causes Dynamic Fee Decay Failure","author":"Viridis"},{"number":326,"title":"Double-counting in `rebalance()` causes permanent DoS and enables interest rate arbitrage that drains liquidity provider yields","author":"Orionn"},{"number":335,"title":"DexV2 Will Not Be Able to Support Tokens Not Configured on the Liquidity Contract","author":"0xBoraichoT"},{"number":347,"title":"Fee Rounding Precision Loss Causes Protocol & LP Fees to Be Withheld from Liquidity Layer in D4 Pool","author":"ElijahO"},{"number":358,"title":"# NFT State Manipulation During Liquidation via DEX Callback Enables Position Theft","author":"kkon82"},{"number":365,"title":"Liquidation does not prioritize lowest LTV tokens","author":"SOPROBRO"},{"number":367,"title":"`FluidDexV2D3UserModule#deposit()` and `#withdraw()` doesn't have `_onlyWhitelistedUsers` modifier","author":"Silvermist"},{"number":394,"title":"Liquidation Allows Selecting Collateral That Decreases Health Factor, Enabling Griefing Liquidations That Move Positions Further From Solvency","author":"heavyw8t"},{"number":395,"title":"Liquidator will steal collateral from wrong position when same-index liquidation causes array shuffle","author":"Stillingsen"},{"number":396,"title":"`FluidMoneyMarket#operate()` minimum amount check blocks withdraw-all, payback-all and fee-collect","author":"Silvermist"},{"number":428,"title":"`DexV2#_calculateDynamicFeeVariables()` 15-bit timestamp storage causes incorrect decay calculation after multiple wraps leading to mispriced swaps","author":"Silvermist"},{"number":430,"title":"`DexV2#settle()` clears pending transfers before Liquidity settlement and does not revert on failure","author":"Silvermist"},{"number":431,"title":"`D2#_swapOut()` uses uninitialized `amountIn_` in reserve checks","author":"Silvermist"},{"number":438,"title":"Attackers can grief the protocol and create \"free\" options by creating many extremely small positions that are un-liquidatabel","author":"heavyw8t"},{"number":441,"title":"Asymmetric rounding in D3/D4 cap accounting creates cumulative upward drift toward cap exhaustion","author":"ranzo"},{"number":468,"title":"Liquidations can be DOSed by opening enough positions in one NFT","author":"heavyw8t"},{"number":476,"title":"Stale dynamic fee impact persists on idle pools due to 15-bit timestamp wrap","author":"iany0x_sherlock"},{"number":480,"title":"Incomplete withdraw-index adjustment in `liquidate()` when D4 payback deletes a non-last position causes wrong collateral to be seized","author":"ranzo"},{"number":483,"title":"15-bit timestamp wrap prevents dynamic fee decay, causing ~94% LP fee loss","author":"JohnLaw"},{"number":485,"title":"Unprivileged caller can DoS `rebalance(token_)` for authorized operators","author":"K42"},{"number":490,"title":"`LiquidateModule` Incorrect Index Adjustment When Payback Position is Deleted","author":"JuggerNaut"},{"number":499,"title":"Liquidation Position Index Mismatch When Payback Deletes a Non-Last Position Causes Wrong Collateral Seizure","author":"0xsolisec"},{"number":505,"title":"Missing NET_TRANSFERS flag allows attacker to cause rebalance() DoS which can lead to DEX insolvency","author":"luc1jan"},{"number":518,"title":"15-bit timestamp wraparound in `_calculateDynamicFeeVariables` preserves stale `netPriceImpact` causing cascading fee corruption, bidirectional LP/swapper losses, and partial swap DoS","author":"ranzo"},{"number":520,"title":"All swap functions use wrong exchange prices for total supply/borrow raw change calculation when swap0To1_=false","author":"Viridis"},{"number":542,"title":"Token Rebalance DoS via Logic Error causes Protocol Insolvency and Interest Rate Suppression","author":"EtherEngineer"},{"number":544,"title":"Liquidators can leave dust positon","author":"EddiePumpin"},{"number":546,"title":"Native ETH settlement in DexV2 fallback logic will cause permanent rebalance DoS","author":"Albert_Mei"},{"number":557,"title":"Protocol fee is applied on top of LP-fee-inclusive amount (fee-on-fee), causing excessive fee extraction","author":"Cara"},{"number":561,"title":"Protocol fee is incorrectly calculated on LP-fee-inclusive amount, causing excess protocol fee extraction","author":"inallhonesty"},{"number":565,"title":"Unbounded O(N) loops in D3 liquidation path create gas DoS risk for isolated-collateral positions","author":"JohnLaw"},{"number":567,"title":"Debt Ceiling and Utilization Limit Bypass via Dex Local Liquidity Optimization","author":"EtherEngineer"},{"number":570,"title":"Liquidator can steal user's collateral","author":"p1ramide"},{"number":587,"title":"Bypass of isolated collateral invariant allows mixing standard and Isolated assets leading to DoS/Griefing","author":"BoyD"},{"number":593,"title":"15-Bit Timestamp Truncation Allows Complete Bypass of Dynamic Fee Decay Mechanism","author":"dexters"},{"number":595,"title":"D3 whitelist not enforced on deposits, withdraws, and swaps","author":"D4N0GOTHACKED"},{"number":596,"title":"D3 liquidation forces a nonzero withdraw for both tokens","author":"D4N0GOTHACKED"},{"number":605,"title":"Partial Liquidation of D4 Smart Debt Positions Creates Permanently Uncloseable Dust Debt","author":"abdulwahed-sweden"},{"number":611,"title":"Liquidator can seize more value from user using carefully sequenced multistep liquidations, causing losses to user","author":"0xCrypt0nite"},{"number":612,"title":"Position index tracking failure during swap-and-pop deletion leads to reading stale position data and liquidation failures","author":"makeWeb3safe"},{"number":621,"title":"Improper Debt Attribution in Isolated Collateral Mechanism Enables Cap Exhaustion via Dust Deposits","author":"0xBoraichoT"},{"number":626,"title":"M-2: D1/D2 `swap0To1 == false` uses wrong token exchange-price index for raw accounting","author":"SnowX"},{"number":627,"title":"Global operation context is not bound to the operation starter","author":"JohnWeb3"},{"number":628,"title":"ERC721 transfer reentrancy during D3 withdrawals can corrupt `_nftConfigs` via stale `nftConfig` snapshots","author":"JohnWeb3"},{"number":643,"title":"liquidation/operate gas-DoS via unbounded iteration over positions in `_getHfInfo`","author":"JohnWeb3"},{"number":644,"title":"`_addPosition` can clobber owner/index after a mid-operation ERC721 transfer, desyncing NFT state","author":"JohnWeb3"},{"number":652,"title":"Global transient pending-transfer counters allow cross-sender griefing (DoS) during active operations","author":"JohnWeb3"},{"number":655,"title":"Attacker will bypass reserve verification on D2 debt pool swapOut","author":"dahmon"},{"number":656,"title":"Swapped exchange price token indices will cause systematic accounting errors in D1/D2 swap functions","author":"dahmon"},{"number":662,"title":"`DexV2AdminModul::rebalance` function assumes `_unaccountedBorrowAmount` is pre-funded, leading to insufficient balance reverts","author":"bube"},{"number":663,"title":"M-1: D2 `_swapOut` reserve-safety guard uses `amountIn_` before assignment (effectively `+0` instead of `+amtInAdjusted`)","author":"SnowX"},{"number":666,"title":"DOS on liquidation through User Inflated Loop on Arbitrum Liquidation or OOG attack on Ethereum","author":"0xBoraichoT"},{"number":667,"title":"Isolated collateral flag and index not written to storage, breaking intended core functionalities","author":"0xCrypt0nite"},{"number":677,"title":"DexV2 settle() bypasses Liquidity risk parameters by minting unbacked stored-claims on Liquidity-layer reverts, leading to protocol insolvency risk","author":"Drothon"},{"number":680,"title":"An attacker can exhaust the Isolated Cap using a tiny amount of Isolated Collateral plus large borrowing backed by non-isolated collateral, causing a DoS on borrowing for other users.","author":"ZeroTrust"},{"number":685,"title":"moneyMarket::_deletePosition. Stale nftConfig Write-Back Causes ERC721 Ownership Desynchronization","author":"0x04"},{"number":689,"title":"Incorrect fee calculation during `swap()` resulting in fees lower than expected","author":"cu5t0mPe0"},{"number":695,"title":"Liquidation withdraw has no slippage protection for D3 positions","author":"elolpuer"},{"number":701,"title":"User will have collateral locked in MoneyMarket","author":"fgh56ty"},{"number":708,"title":"Insufficient accrued fees will block D3/D4 liquidation, causing bad debt accumulation for the protocol","author":"hackcat"},{"number":726,"title":"Unwhitelisted NFT owner will bypass D4 permission checks and access smart debt pools of the protocol","author":"neeloy"},{"number":733,"title":"Incorrect Position Index Correction Upon Deletion During Liquidation","author":"inspecktor"},{"number":737,"title":"Liquidations do not prioritize lowest LTV collateral, allowing liquidators to worsen position health toward bad debt","author":"velev"},{"number":740,"title":"D3/D4 Liquidation Reverts When Stored Fees Are Zero and Supply Cannot Cover Withdraw Value","author":"velev"},{"number":743,"title":"Attacker will corrupt packed pool state and break D3/D4 pool accounting for LPs/traders","author":"ZeroTrust"},{"number":756,"title":"LPs will experience DoS when depositing or swapping due to tokenReserves accounting drift","author":"ZeroTrust"},{"number":765,"title":"Fee Calculation in swapIn and swapOut causes user to pay less fee when swappingIn.","author":"Bizarro"},{"number":766,"title":"Unfair Liquidation Penalty Distribution Based on Fee token composition","author":"Bizarro"},{"number":773,"title":"Malicious liquidator leaves behind dust amount via partial payback locking legitimate users from accessing certain NFT capabilities","author":"slowpoke"},{"number":774,"title":"Asynchronous exchangePrices Lead to Incorrect health factor Calculation","author":"inspecktor"},{"number":776,"title":"Tick Overflow Corrupts `sqrtPrice` When a 0\u21921 Swap Crosses `MIN_TICK`","author":"rubencrxz"},{"number":782,"title":"missing minimum value check while borrowing allows creation of non-liqudatable debt positions","author":"slowpoke"},{"number":793,"title":"Liquidation position index desync when paybackPositionIndex == withdrawPositionIndex causes wrong collateral seizure or DoS","author":"Jiberish"},{"number":796,"title":"Rebalance Denial of Service After Local Borrow Because Gross Amounts Are Sent Without `NET_TRANSFERS`","author":"rubencrxz"},{"number":805,"title":"Position Index Mismatch After D4 Payback Deletion Causes Wrong Collateral Seizure During Liquidation","author":"velev"},{"number":806,"title":"D3/D4 cap occupancy can be griefed upward via rounding asymmetry, causing pool-level liquidity-increase DoS","author":"antigone4224"},{"number":813,"title":"Liquidators will over- or under-liquidate borrowers due to pool/oracle price mismatch","author":"LeoGold"},{"number":819,"title":"BigNumber Precision Loss Causes Arithmetic Underflow in Cap Accounting, Blocking Paybacks and Collateral Withdrawal","author":"zvizr"},{"number":822,"title":"Any D2 swapper will bypass reserve-safety checks for D2 LPs and protocol accounting","author":"0xDyDx"},{"number":823,"title":"Any D2 swapper will skew raw debt accounting for D2 LPs and protocol risk controls","author":"0xDyDx"},{"number":829,"title":"Borrower can create unliquidatable position","author":"EddiePumpin"},{"number":838,"title":"Liquidation eligibility and post-conditions for D3/D4 positions can be wrong because HF decomposes positions using an oracle-implied `sqrtPriceX96` while liquidation uses the pool `sqrtPriceX96`.","author":"0xepley"},{"number":875,"title":"Malicious liquidator will seize collateral without reducing debt for borrowers","author":"neeloy"},{"number":878,"title":"Uncloseable Dust Positions Due to Minimum Amount Check Applied to \"ALL\" Sentinel","author":"nitinaimshigh"},{"number":879,"title":"Rubyglask - D2._swapOut() uses uninitialized amountIn_ (= 0) in reserve verification, bypassing MINIMUM_LIQUIDITY_SWAP check","author":"Rubyglask"},{"number":882,"title":"Token Reserves Inflation Due to Unaccounted Fee Accrual","author":"Kenn.eth"},{"number":884,"title":"Native Token Rebalance Permanently Reverts When Unaccounted Borrows Exist - Protocol Accounting Divergence","author":"Theseersec"},{"number":886,"title":"D4: Permissionless swap drain when borrow exchange prices diverge","author":"hirusha"},{"number":892,"title":"[M-1] Token Reserves Accounting Ignores Fee Distributions \u2014 Monotonically Growing Reserve Overstatement Degrades Pool Safety and Token Delivery","author":"CryptoGuardian"},{"number":895,"title":"15-bit Timestamp Wrap-around Corrupts Dynamic Fee Decay and Enables Fee Evasion or Exploitation","author":"gelenbedalen"},{"number":896,"title":"Permanent DoS of Critical Rebalance Functions via nativeTokenAllowances Precision Mismatch","author":"gelenbedalen"},{"number":900,"title":"D3 Collateral with Zero LP and Zero Fees Cannot Be Liquidated","author":"uba"},{"number":909,"title":"Precision mismatch in nativeTokenAllowances leads to permanent DoS of critical rebalance functions","author":"gelenbedalen"},{"number":914,"title":"Dynamic Fee Timestamp Truncation (15-bit) Breaks Net-Price-Impact Decay After ~9.1 Hours, Allowing Abnormally Prolonged Dynamic Fees","author":"kimnoic"},{"number":917,"title":"Malicious borrower will force liquidation underpayment for liquidators","author":"neeloy"},{"number":925,"title":"MIN_TICK` overflow corrupts dex vars","author":"r0bert"},{"number":937,"title":"CurrentTick MIN_TICK underflow corrupts packed dexVariables (19-bit overflow)","author":"Tupaia"},{"number":941,"title":"`NORMAL_BORROW` liquidation payback can round `paybackAmountRaw_` to 0 while still seizing collateral, leaving Money Market debt unchanged (\u201crepay without reducing debt\u201d)","author":"kimnoic"},{"number":944,"title":"Asymmetric rounding in cap accounting can accumulate \u201ccap dust\u201d, enabling cap-griefing DoS","author":"kimnoic"},{"number":945,"title":"Liquidation Path Dependence: choosing collateral withdrawal path can worsen HF and increase bad debt risk","author":"taticuvostru"},{"number":946,"title":"User will permanently lock dust supply collateral for affected party (themselves) causing unwithdrawable stuck funds","author":"yaioxy"},{"number":947,"title":"Protocol will accrue bad debt from dust borrow positions that can neither be liquidated nor repaid","author":"yaioxy"},{"number":951,"title":"A liquidator will worsen borrower health factor  by choosing high-LT collateral","author":"Thisisit"},{"number":960,"title":"Off-by-One at Protocol's Own MIN_TICK Boundary Causes Silent Storage Corruption in D3/D4 Pools","author":"Pelz"},{"number":971,"title":"Attacker will constanly block DexV2.rebalance(token) for a token as they poison borrows by setting to = address(dexV2)","author":"AV"},{"number":973,"title":"Non-Proportional Fee Seizure in D3/D4 Liquidations Causes Excess Loss for Position Owners","author":"0xRstStn"},{"number":974,"title":"Swappers can corrupt packed pool state by crossing MIN_TICK in tickSpacing = 1 pools","author":"LeoGold"},{"number":975,"title":"Liquidation can withdraw from the wrong position (or revert) when D4 payback deletes a position and `paybackPositionIndex == withdrawPositionIndex`.","author":"0xepley"},{"number":981,"title":"Trader will pay higher fees when using `_swapOut` than `_swapIn`","author":"0xmelody"},{"number":982,"title":"LP fees are calculated wrongly during a swap leading to a loss of fees","author":"Audinarey"},{"number":985,"title":"Minimum Amount Limit + Conservative Rounding Can Create Uncloseable Dust Positions","author":"kimnoic"},{"number":1011,"title":"rebalance() reverts due to missing NET_TRANSFERS flag when accumulated D4 swapIn fees exceed Dex token balance","author":"maigadoh"},{"number":1017,"title":"Liquidity Providers lose 100% of fees on small swaps due to aggressive protocol cut rounding","author":"eryxxxxx"},{"number":1019,"title":"Dust-debt poisoning via `1e4` minimum amount gate and malicious liquidators will lock collateral for MoneyMarket borrowers","author":"fuzious"},{"number":1020,"title":"Unprotected Slippage in D3 Collateral Liquidation Withdrawals Leads to Loss","author":"0xpetern"},{"number":1026,"title":"Near dust normal supply collateral positions can be permanently locked because of verifyamountlimits enforcement","author":"slowpoke"},{"number":1029,"title":"Liquidation Allows Same Position Index for Payback and Withdraw, Leading to Wrong Collateral Seizure After Position Deletion","author":"Jumcee"},{"number":1032,"title":"Array Compaction Causes Liquidation to Target Incorrect Position","author":"SOPROBRO"},{"number":1040,"title":"Out-of-range tick value causes packed storage corruption when crossing `MIN_TICK`","author":"natachi"},{"number":1041,"title":"Liquidator will be unable to liquidate D4 positions with zero fees, causing bad debt for the protocol","author":"0xJason"},{"number":1044,"title":"Swap crossing MIN_TICK will corrupt pool state for all LPs and swappers as the unchecked tick decrement overflows the 19-bit packed storage field","author":"0xJason"},{"number":1048,"title":"Rounding Error in 1:1 Swaps Causes User Fund Loss and Breaks Invariants","author":"Holmes7002"},{"number":1057,"title":"Liquidation can withdraw from the wrong position (or revert) when D4 payback deletes a position and `paybackPositionIndex == withdrawPositionIndex`.","author":"auditbase"},{"number":1063,"title":"D1 and D2 swap functions use swapped exchange prices for token1\u2192token0 direction, corrupting totalSupplyRaw/totalBorrowRaw","author":"Jiberish"},{"number":1064,"title":"D2 _swapOut uses uninitialized amountIn_ (value 0) in reserve verification, bypassing reserve balance checks","author":"Jiberish"},{"number":1066,"title":"rebalance Reverts When supplyAmount is Greater Than Actual Balance, Blocking Liquidity Sync and Rate Updates","author":"ExtraCaterpillar"},{"number":1072,"title":"Withdraw of D3 Collateral in Liquidation Lacks Minimum Output Protection","author":"ExtraCaterpillar"},{"number":1075,"title":"DEX V2 cannot support tokens permissionlessly","author":"ExtraCaterpillar"},{"number":1078,"title":"Liquidators can selectively seize high-LTV collateral, leaving borrowers with riskier portfolios","author":"0xh4153c"},{"number":1087,"title":"Rebalance DoS Due to Arbitrary Calls to DexV2 settle that can manipulate the accounting state of DEX","author":"Riceee"},{"number":1091,"title":"Borrow Rate Limit Bypass Leads to Rebalance DoS, which can even occur during D4 protocol operations.","author":"Riceee"},{"number":1094,"title":"DexV2: `rebalance()` reverts when `settle()` accrues `_unaccountedBorrowAmount > _totalAuthAddedAmount`, bricking rebalancing for the token","author":"Edoscoba"},{"number":1097,"title":"Unpayable \u201cDust Debt\u201d Can Permanently Lock Collateral","author":"Edoscoba"},{"number":1103,"title":"Dynamic-Fee Timestamp Compression Undercharges LP Fees After ~9h Inactivity","author":"Edoscoba"},{"number":1105,"title":"Dust Fee Stored in D3/D4 Positions Permanently Blocks Position Deletion","author":"Waydou"},{"number":1110,"title":"Unguarded ERC721 entrypoints allow mid-operation NFT transfers that get overwritten by stale `nftConfig` writebacks, enabling position ownership rollback, theft, and ERC721 state corruption","author":"xiaoming90"},{"number":1112,"title":"D4 Fee-Only Liquidation Path Reverts When No Fees Have Accrued","author":"PowPowPow"},{"number":1113,"title":"Crossing `MIN_TICK` in `swap0To1` underflows `currentTick` and corrupts packed `dexVariables`","author":"xiaoming90"},{"number":1115,"title":"User withdrawals can stay locked even when the DEX has enough tokens","author":"0xnija"},{"number":1116,"title":"Unbounded per-NFT position iteration enables gas DoS of liquidation and HF-gated operations, creating unliquidatable bad debt","author":"xiaoming90"},{"number":1131,"title":"D3 Liquidation Uses Pool Price for Collateral Estimation While Post-Liquidation HF Check Uses Oracle Price, Causing Liquidations to Revert","author":"natachi"},{"number":1150,"title":"Dust Borrow Positions Become Permanently Undeletable Due to Amount Limit Check on Payback","author":"Waydou"},{"number":1158,"title":"Liquidation can seize an unintended position when payback deletes and `withdrawPositionIndex == paybackPositionIndex`","author":"xiaoming90"},{"number":1159,"title":"`_useFeeStoredForLiquidation` Uses Individual Token Penalties Instead of Average, Causing Value Extraction Discrepancies","author":"Emmanuel"},{"number":1162,"title":"Minimum fee-collection amount check makes fees uncollectable and permanently prevents D3/D4 position deletion","author":"xiaoming90"},{"number":1166,"title":"An attacker can create unliquidatable borrow positions and permanent bad debt","author":"lodelux"},{"number":1169,"title":"Double Liquidation Penalty in D3 Liquidation","author":"pashap9990"},{"number":1170,"title":"MIN_TICK underflow on tick crossing can corrupt packed `currentTick` storage","author":"jo13"},{"number":1175,"title":"Negative Tick Initialization Corruption","author":"BensonDynasty"},{"number":1178,"title":"Monotonic Cap Drift in D3/D4 Position Cap Tracking Permanently Blocks Deposits","author":"Waydou"},{"number":1182,"title":"Collateral fragmentation can permanently block underwater liquidations","author":"xiaoming90"},{"number":1185,"title":"settle() netAmount == 0 fallback can permanently desync Dex vs Liquidity and make rebalance impossible","author":"xiaoming90"},{"number":1194,"title":"Inconsistent price sources between HF calculation and liquidation will cause bad debt for the protocol","author":"DeltaPrime"},{"number":1202,"title":"`rebalance` incorrectly sends the \"Gross Amount\" when handling ETH, leading to an insurmountable `Insufficient Balance` exception","author":"songyuqi"},{"number":1206,"title":"Incorrect token sync accounting in `rebalance()` sends incorrect amount, permanently bricking token reconciliation.","author":"Harry-Elite"},{"number":1209,"title":"Liquidator-controlled collateral selection in `liquidate()` allows collateral ordering to amplify borrower losses beyond the minimum necessary.","author":"Harry-Elite"},{"number":1216,"title":"Liquidator can massively increase borrower's loss by targeting High-LT Collateral in a multi-collateral Position","author":"0xRstStn"},{"number":1220,"title":"Fragmented micro-collateral positions create economically unliquidatable positions.","author":"Harry-Elite"},{"number":1225,"title":"MoneyMarket D3: ETH-settle reentrancy clobbers ERC721 ownership via stale `nftConfig` writeback","author":"Edoscoba"},{"number":1229,"title":"D3 Whitelist Bypass Allows Unauthorized Deposits/Withdrawals via Callback Route","author":"agent_mino"},{"number":1232,"title":"Missing Remaining Debt Validation in Payback Flow Allows Creation of Permanently Unliquidatable Positions","author":"la-arana-inteligente"},{"number":1234,"title":"A malicious user can deposit collateral into multiple positions to prevent liquidations.","author":"0xBoraichoT"},{"number":1235,"title":"Crossing MIN_TICK corrupts _dexVariables packed state with out of range tick value","author":"iamephraim"},{"number":1237,"title":"Fee Base Asymmetry (\u201cfee-on-fee\u201d) in swapOut vs swapIn: swapOut computes protocol fee on LP-fee-grossed amountIn","author":"AV"},{"number":1254,"title":"\"Negative Tick Bitmap Corruption via Unsafe Modulo Operation\"","author":"neme"},{"number":1262,"title":"Normal Supply Cap Counter Drifts Upward Permanently After Each Position Cycle, Enabling Deposit DoS","author":"PowPowPow"},{"number":1273,"title":"`MIN_TICK - 1` underflow corrupts persisted `dexVariables` (tick lane spills into sqrtPrice lane)","author":"Baazigar"},{"number":1276,"title":"`_setTickBitmap()` doesn't handle negative tick properly","author":"WillyCode20"},{"number":1293,"title":"Any address will bypass D3 whitelist and add/remove liquidity for the protocol","author":"Tenalia-Audits"},{"number":1298,"title":"Attacker can liquidate positions in a strategic way to worsen position health and liquidated more than necessary.","author":"Tenalia-Audits"},{"number":1310,"title":"`liquidate` function  allows the liquidator to choose which collateral to seize","author":"khaye26"},{"number":1315,"title":"Multi-position liquidation can seize the wrong collateral when payback deletes a non-last position (swap-and-pop index corruption)","author":"Blackdruid"},{"number":1321,"title":"Negative-Tick Bitmap Corruption","author":"iceprince8175"},{"number":1332,"title":"borrower will be unable to fully withdraw collateral due to unpayable residual debt","author":"MohammadX2049"},{"number":1350,"title":"Crossing `MIN_TICK` in `swap0To1` underflows `currentTick` to `MIN_TICK - 1`, corrupting packed `dexVariables` and causing persistent swap DoS","author":"thimthor"},{"number":1356,"title":"Users will pay more fees with swapOut instead of swapIn, for the exact same swap","author":"lodelux"},{"number":1357,"title":"LP will charge more fees to trader","author":"proofvoid"},{"number":1374,"title":"Unbounded Position Loop in `_getHfInfo` Allows Permanent DoS of Liquidation Mechanism","author":"sourav_DEV"},{"number":1376,"title":"Protocol will seize 100% of fees from Liquidity Providers on small trades due to aggressive rounding","author":"nnoy"}]}]
