Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Cantina
CodeHawks
Hats Finance
Nov '24
medium
medium
May '24
Apr '24
Mar '24
Feb '24
Jan '24
high
When borrowers repay USDS, it is sent to the wrong address, allowing anyone to burn Protocol Owned Liquidity and build bad debt for USDS
high
User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated
high
The use of spot price by CoreSaltyFeed can lead to price manipulation and undesired liquidations
medium
formPOL lacks slippage and deadline protection
medium
Chainlink price feed uses BTC, not WBTC. In case of depegging, oracles will become easier to manipulate.
medium
Remove Liquidity has missing reserve1 DUST check, which can make reserve1 to be less than DUST
Dec '23
Oct '23
high
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
high
Attacker can reenter to mint all the collection supply
high
Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders
medium
On a Linear or Exponential Descending Sale Model, a user that mint on the last `block.timestamp` mint at an unexpected price.
medium
Vulnerability in burnToMint function allowing double use of NFT
medium
The RandomizerVRF and RandomizerRNG not produce hash value.
medium
Auction winner can prevent payments via `safeTransferFrom` callback