
Payouts

1st Places

2nd Places

3rd Places
All
Sherlock
Code4rena
Apr '26
Mar '26
Feb '26
high
Jan '26
high
Variable Overwrite in checkPoolAndGetCenterPrice() Creates Dead-Code Deviation Check, Leaving All V3 Protocol-Owned Liquidity Operations Unprotected
high
UniswapPriceOracle.validatePrice() TWAP Calculation Flaw
high
Incorrect TWAP calculation in BalancerPriceOracle allows price manipulation and breaks oracle guarantees
Findings not publicly available for private contests.
Dec '25
high
high
high
medium
medium
Nov '25
Oct '25
Sep '25
Findings not publicly available for private contests.
Aug '25
Jul '25
May '25
Apr '25
Mar '25
Feb '25
Jan '25
Dec '24
Nov '24
Oct '24
Sep '24
Aug '24
medium
`ChainlinkEthOracle` and `ChainlinkUsdOracle` did not check `minAnswer` and `maxAnswer`, this may cause wrong price
medium
The `superPool` contract cannot be `paused` and `unpaused` completely when needed (i.e. `superPool` is hacked) because none of the functions in it use the `whenNotPaused` and `whenPaused` modifiers
Jul '24
Apr '24
Mar '24
Feb '24
Jan '24
Dec '23
Oct '23
Sep '23