Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
CodeHawks
Feb '25
high
Wrong refundExecutionFee in _handleReturn
high
Deposits on long one leverage vault don't actually finalize the flow, leading to a Denial of Service (DoS)
high
Loss of fee refund due to premature state deletion in `PerpetualVault::_handleReturn` function
medium
Wrong index causes last depositor to always get execution fee refund if cancelFlow is called by keeper to cancel a withdrawal
Jan '25
high
Oct '24
high
high
high
medium
Aug '24
high
Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function
high
TokenManager - Unlimited withdraw
high
Taker of bid offer will loss assets without any benefit if he calls the DeliveryPlace::settleAskMaker() for partial settlement.
high
Native token withdrawal fails until manually approved
high
`DeliveryPlace::settleAskTaker` Has Incorrect Access Control
high
Malicious user can drain protocol by bypassing `ASK` offer abortion validation in `Turbo` mode
high
The `DeliveryPlace::settleAskTaker()` function mistakenly uses `makerInfo.tokenAddress` to update the `TokenBalanceType.PointToken` in the `userTokenBalanceMap` mapping, leading to a critical error.
high
[H-4] The function `PreMarkets::listOffer` charges an incorrect collateral amount, allowing users to manipulating collateral rates and drain the protocol's funds
Jul '24
Jun '24
Feb '24
Sep '23
Jul '23
1,327.73 USDC • 1 total finding • CodeHawks • 0xrststn
#5