Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Code4rena
Feb '25
Jan '25
high
The calculation of `totalAssets()` could be wrong if `operatorFeeAmount` > 0, this can cause potential loss for the new depositors
medium
User can earn rewards by frontrunning the new rewards accumulation in Ron staking without actually delegating his tokens
medium
Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions
Dec '24
Nov '24
Oct '24
Sep '24
Aug '24
Jul '24
high
Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens
high
Invalid validation allows users to unlock early
high
in `farmPlots()` an underflow in edge case leading to freeze of funds (NFT)
high
Invalid validation in _farmPlots function allowing a malicious user repeated farming without locked funds
May '24
high
Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens
high
Invalid validation allows users to unlock early
high
in `farmPlots()` an underflow in edge case leading to freeze of funds (NFT)
high
Invalid validation in _farmPlots function allowing a malicious user repeated farming without locked funds
Apr '24
high
Incorrect withdraw queue balance in TVL calculation
high
Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps
high
Incorrect calculation of queued withdrawals can deflate TVL and increase ezETH mint rate
medium
Deposits will always revert if the amount being deposited is less than the bufferToFill value
Mar '24
Feb '24
high
Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win
high
Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes
high
Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`
medium
Can mint NFT with the desired attributes by reverting transaction
Jan '24