Payouts
Top 25
Top 50
All
Sherlock
CodeHawks
Jul '23
high
Sandwich attack to steal all ERC-20 tokens in the Fees contract
high
During refinance() new Pool balance debt is subtracted twice
high
[H-04] Lender#buyLoan - Malicious user could take over a loan for free without having a pool because of wrong access control
high
Using forged/fake lending pools to steal any loan opening for auction
high
Attacker can steal a loan's collateral and break the protocol
medium
The `borrow` and `refinance` functions can be front-run by the pool lender to set high interest rates
51.32 USDC • 3 total findings • CodeHawks • 0xDanielH
#40
2.47 USDC • 1 total finding • CodeHawks • 0xDanielH
#94