Payouts
Top 25
Top 50
All
Sherlock
Jul '25
high
Uses asset.balanceOf(address) even in the case of ETH
high
The protocolFees are deducted from the users multiple times for the same period.
high
decrementing `latestEligibleIndex` results in skipping the assets that was supposed to included with latest price
high
users can provide duplicate `signatures` to pass the consensus's threshold limit.
medium
User who is allowed to transfer when the transferWHitelistFlag is set cannot actually transfer.
medium
Attacker can DoS user from redeeming shares if user holds climableShares.
medium
disallowing an asset from a subvault leads to the DoS of `redeemQueue.handleBatch()` Operation.
medium
SignatureRedeemQueue doesnt have receive() fn - Unable to redeem shares in eth