Payouts
1st Places
Top 10
Top 25
All
Sherlock
Jun '25
May '25
high
Malicious user can drain `CoreRouter` contract's LEND tokens, causing other users to be unable to claim their LEND tokens
high
Malicious user can steal `CoreRouter` liquidity, resulting in LPs unable to fully withdraw their supplied liquidity
high
Malicious user can borrow more than `maxBorrow` as `LendStorage::userCrossChainBorrows` is updated without accounting for the interest of the previous borrow
high
Cross-chain liquidations will fail as `CrossChainRouter::_handleLiquidationExecute` sends wrong payload to destination chain
Nov '24
94.59 USDC • 1 total finding • Sherlock • 37H3RN17Y2