Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
CodeHawks
Mar '25
Feb '25
Jan '25
Dec '24
high
Attacker Can Exponentially Increase Cumulative Rate in `Borrowing` contract
high
Incorrect State Update in `ABONDToken.transferFrom` Function
high
Lack of Access Control in `CDS.updateDownsideProtected()` Function
high
Logical Error in Timestamp Condition for Option Renewal `BorrowLib.getOptionFeesToPay()`
high
Potential Locking of Liquidation Interest Funds in `Treasury` Contract For Ever
medium
Inconsistent Updates to `omniChainData.totalVolumeOfBorrowersAmountinWei` in `BorrowLib` cause system wide accounting issues
medium
Inconsistent Use of `lastCumulativeRate` in `depositTokens()` and `withdraw()` Functions in `Borrowings` Contract
medium
Incorrect Update of `lastEventTime` in `Borrowings.withDraw()` Function
Nov '24
Findings not publicly available for private contests.
Oct '24
Aug '24
high
An attacker can cancel any raffle immediately after the prize manager locks the prize.
high
An attacker will lock prizes indefinitely in the `WinnablesPrizeManager` contract and restrict winner from claiming their prizes
medium
Old Owners Retain Unauthorized Access to Critical Functions in `WinnablesPrizeManager` and `WinnablesTicket` Contracts
Jul '24
high
`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`
high
Incorrect Percentage Calculation in NukeFund and EntityForging when `taxCut` is Changed from Default Value
medium
Pause and unpause functions are inaccessible
Jun '24
Findings not publicly available for private contests.
May '24
Apr '24
high
Incorrect withdraw queue balance in TVL calculation
high
Incorrect calculation of queued withdrawals can deflate TVL and increase ezETH mint rate
medium
Pending withdrawals prevent safe removal of collateral assets
medium
Deposits will always revert if the amount being deposited is less than the bufferToFill value
Mar '24
Feb '24
Jan '24
Nov '23
207.11 USDC • 1 total finding • Code4rena • 0xAadi
#17
Oct '23
Sep '23