Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Code4rena
CodeHawks
May '25
Mar '25
Feb '25
medium
Missing Slippage Protection On Buy And Sell
medium
`AgentDAO::_castVote` doesn't check the array of votes emitted, which determine the number of battles fought in `EloCalculator.sol`, allowing the user to increase the ELO of a contribution unfairly, inflating the maturity/impact of `ServiceNFTs`
high
`BaseGauge` users can claim rewards without staking
high
`GaugeController` does not send funds to FeeCollector disrupting fees distribution and causing loss of funds
high
Voting Power Snapshot Missing
medium
Timelock Controller Retains Canceled Proposals, Enabling Unauthorized Execution and severe Governance Voting manipulation.
medium
Missing Vote Frequency Control in GaugeController
medium
`MAX_TOTAL_SUPPLY` Bypass in `veRAACToken` via `increase()` Function
medium
veRaac Token Constraint MAX_TOTAL_SUPPLY Can Be Bypassed. Vulnerability Disrupts Protocol Functionality and Undermines Governance Quorum.
medium
Incorrect DebtToken totalSupply Scaling Breaks Interest Rate Calculations
medium
LendingPool deposits do not work with CurveVault due to lack of funds
medium
Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations
medium
Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator
medium
Token Accounting Mismatch Between tick() and mintRewards() in RAACMinter
medium
Inconsistent Scaling in RToken Transfer Functions
medium
Delegated Boost Persists Even If veRAAC Is Withdrawn/Reduced
medium
[L-1] Inaccurate boost calculations in `veRAACToken` due to wrong input parameter
medium
Cordinated group of attacker can artificially lower quorum threshold during active proposals forcing malicious proposals to pass without true majority support.
medium
balanceOf(address(this)) in StabilityPool causes reward distribution to be higher than it should be
low
Limited veRaac Token Supply Triggers DoS, Hampering Proper Governance Participation.
low
Emergency Timelock Bypass: No Enforced 1-Day Delay for Emergency Actions
low
Lack of enforcement of the `MAX_TOTAL_LOCKED_AMOUNT`
low
Missing Controller Functions in GaugeController
low
Unauthorized Vote Casting Vulnerability
low
Missing Pause Functionality in veRAACToken Contract Can Be Abused When Emergency Withdrawal Mechanism Is Activated
low
Incorrect Timestamp Tracking in RAACHousePrice contract
low
Missing `BaseGauge::distributionCap` validation leads to over-emission of rewards
low
Missing Validation for Minimum Vote Weight in `vote` Function
low
`emergencyUnlockEnabled` Is Never Used, Rendering “Emergency Unlock” Ineffective
Jan '25
Dec '24
Nov '24
Oct '24