Payouts
2nd Places
3rd Places
Top 10
All
Code4rena
Mar '23
Jan '23
Dec '22
Nov '22
Oct '22
Sep '22
Aug '22
Jul '22
Jun '22
May '22
high
RubiconRouter: Offers created through offerWithETH() can be cancelled by anyone
medium
USDT is not supported because of approval mechanism
medium
Strategists can't be removed
medium
No cap on fees can result in a DOS in BathToken.withdraw()
medium
Admin rug vectors
medium
Use `safeTransfer()`/`safeTransferFrom()` instead of `transfer()`/`transferFrom()`
medium
`RubiconMarket.feeTo` set to zero-address can DoS `buy` function
medium
```withdrawForETH``` could be used to drain the WETH in ```RubiconRouter.sol```
medium
Wrong DOMAIN_SEPARATOR
medium
Centralized risks allows rogue pool behavior in BathToken.
medium
BathBuddy locks up Ether it receives
medium
Use `call()` instead of `transfer()` when transferring ETH in RubiconRouter
medium
User will loose funds
Apr '22
Mar '22
Feb '22
Jan '22
Dec '21
Nov '21