Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Feb '25
Dec '24
high
Arbitrary Price Input in CDS Redeem Function Allows Exchange Rate Manipulation
high
Missing Access Control on updateDownsideProtected() Enables Critical Pool Manipulation in CDS Protocol
high
Missing Replay Protection in ODOS Swap Authorization
high
LayerZero Message Delays Can Cause Protocol Issues Through Cross-Chain State Desynchronization
medium
Unbounded Liquidation Iterations Can Lead to Withdrawal DoS
Nov '24
Oct '24
Sep '24
high
Listings Contract will erroneously attempt to deposit fees and issue refunds when relisting a liquidated listing
high
Malicious user can exploit stale listings to gain undue refunds, impacting protocol funds and listing integrity
high
Users will suffer unexpected liquidations and unfair interest charges on Protected Listings
medium
User can cancel or modify Dutch auctions, compromising market integrity and user trust
Aug '24
high
Liquidity Vault will accumulate inaccessible Pegged Assets (PA) affecting users funds
high
Lack of exchange rate consideration during lvRedeemRaWithCtDs will cause loss for users and protocol
high
Missing RA balance update for PSM during LV redemptions will cause incorrect RA balance
high
Protocol will lose access to repurchased RA tokens after issue expiry, impacting CT holders.
high
Incorrect value from emptyReservePartial may cause user redemption requests to be blocked in LV
medium
User can manipulate initial RA/CT AMM price, causing significant loss to the protocol and other users