Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Cantina
CodeHawks
Feb '25
Jan '25
high
Invalid `period` used in `Pool::transferReserveToAuction(...)` function leads to DoS of the `Auction` contract
high
Plaza token creation can be gamed when collateral level is <= 1.2
medium
Base mainnet ChainLink oracle is incompatible with `wstETH` causing issues for fetching the reserve token price
medium
Blacklisted `USDC` user could DoS the `Auction` contract
medium
Stuck funds in `BalancerRouter` when user exceeds `PreDeposit` deposit cap
medium
`BondEth` holders could end up claiming other users' `couponTokens`
medium
Precission loss in the Pool contract
Dec '24
Nov '24
94.59 USDC • 1 total finding • Sherlock • 056Security
Oct '24
high
medium
Sep '24
high
medium
Aug '24
high
Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function
high
Taker of bid offer will loss assets without any benefit if he calls the DeliveryPlace::settleAskMaker() for partial settlement.
high
Native token withdrawal fails until manually approved
high
`DeliveryPlace::settleAskTaker` Has Incorrect Access Control
high
Malicious user can drain protocol by bypassing `ASK` offer abortion validation in `Turbo` mode
high
The `DeliveryPlace::settleAskTaker()` function mistakenly uses `makerInfo.tokenAddress` to update the `TokenBalanceType.PointToken` in the `userTokenBalanceMap` mapping, leading to a critical error.
high
[H-4] The function `PreMarkets::listOffer` charges an incorrect collateral amount, allowing users to manipulating collateral rates and drain the protocol's funds
high
Taker of bid offer will loss assets without any benefit if he calls the DeliveryPlace::settleAskMaker() for partial settlement.
high
`DeliveryPlace::settleAskTaker` Has Incorrect Access Control
high
Formulaic Error Rounds Down Causing Total Loss Of Funds For Bid Takers During Abort
high
The `DeliveryPlace::settleAskTaker()` function mistakenly uses `makerInfo.tokenAddress` to update the `TokenBalanceType.PointToken` in the `userTokenBalanceMap` mapping, leading to a critical error.
high
Missing abort status check allows bid taker to steal users funds
low
`listOffer` Unsafely References Fungible Identifiers
Jul '24
high
`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`
high
The maximum number of generations is infinite
medium
Users' ability to nuke will be DoSed for three days after putting NFTs up for sale and cancelling the sale
medium
Forger Entities can forge more times than intended
medium
Duplicate NFT generation via repeated forging with the same parent
medium
`Golden God` Tokens can be minted twice per generation
high
Number of entities in generation can surpass the 10k number
high
Wrong minting logic based on total token count across generations
medium
Forger Entities can forge more times than intended
medium
Duplicate NFT generation via repeated forging with the same parent
medium
Imprecise token age calculation results in an incorrect nuke factor, causing users to claim the wrong amount
Jun '24
May '24