Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Blackthorn
Code4rena
Feb '25
Collaborative Audit • Blackthorn • 0x007
Dec '24
Nov '24
high
Inconsistent State Management: EthereumTx StateDB Overriding CallContract Results
high
Gas is not consumed when precompile method fail, allowing resource consumption related DOS
high
Unlimited Nibi could be minted because evm and bank balance are not synced when staking
high
Hardcoded gas used in ERC20 queries allows for block production halt from infinite recursion
medium
Nibiru's bank coin to EVM balance tracking logic is completely broken for rebasing tokens and would lead to leakage/loss of funds when converting
medium
ERC20 Transfer Fails With Non-Compliant Tokens Missing Return Values
Aug '24
Apr '24
Dec '23
Findings not publicly available for private contests.
Oct '23
Jul '23
high
LMPVaultRouterBase would still pull WETH token after processing ETH in
high
Liquidation mechanism is useless cause any arbitrary address can call IBaseRewardPool.getRewards
high
Curve V2 Vaults can be drained because CurveV2CryptoEthOracle can be reentered with WETH tokens
high
LiquidatorRow.liquidateVaultsForToken won't work cause tokens are not transferred to asyncSwapper
high
It is possible to lock in loss for other users by not calling updateDebtReporting before withdraw
high
Rewards of LMPVault in DestinationVault.rewarder could be stolen with flashloan
high
Formula for collecting fee in LMPVault._collectFees is wrong
medium
LMPVault.updateDebtReporting could underflow because of subtraction before addition
high
Incorrect liquidation reward computation causes excess liquidator rewards to be given
high
Funds are locked because borrowFee is not correctly implemented in BigBang
medium
`ARBTriCryptoOracle` is vulnerable to read-only reentrancy
medium
There is no mechanism to track and resolve bad debt
medium
`SGLBorrow::repay` and `BigBang::repay` uses `allowedBorrow` with the asset amount, whereas other functions use it with share of collateral
medium
[MB01] Inadvised hardcoding of pool address in `AaveStrategy.sol`
Jun '23
May '23
Apr '23
Nov '22
Oct '22