Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Feb '25
high
Reward manipulation vulnerability in StabilityPool
high
NFTs Get Permanently Locked in Stability Pool After Liquidation
medium
LendingPool deposits do not work with CurveVault due to lack of funds
medium
Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check
medium
There is no logic checking for RAACNFT price staleness before minting it
medium
LendingPool.getUserDebt returns outdated value and can lead to liquidation failure
medium
Missing Liquidity Rebalancing in Repayments and Liquidations Leading to Inefficient Liquidity Management
medium
The endAuction function attempts to send native tokens to the StabilityPool, which does not support
low
`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types
low
Incorrect Timestamp Tracking in RAACHousePrice contract
Jan '25
high
Dec '24
Oct '24
medium
Users can list assets with price < 1 ERC20 (ETH, WETH), leading to potential DoS vulnerability.
low
Lack of output validation in `LLMOracleCoordinator::respond` allows empty responses and potential fee exploitation by oracles.
low
`LLMOracleCoordinator::request` lacks a check for non-empty `task.input`, making `assertValidNonce` easier to pass due to reduced uniqueness
Aug '24
Jul '24
Jun '24
May '24
high
Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens
high
Invalid validation allows users to unlock early
medium
Missing disapproval check in `LockManager.sol::approveUSDPrice` allows simultaneous approval and disapproval of a price proposal
medium
Players can gain more NFTs benefiting from that past remainder in subsequent locks
Apr '24
Mar '24
Feb '24
Jan '24
Dec '23
Nov '23
Oct '23
Sep '23
Aug '23
Jul '23
13.36 USDC • 5 total findings • CodeHawks • 0xhacksmithh
#69
Jun '23
May '23
Apr '23
Mar '23
Feb '23
Jan '23
Dec '22
Nov '22