
Payouts

3rd Places

Top 10

Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Oct '25
Sep '25
Aug '25
high
Users could increase their collateral/decrease their borrow in any market by using malicious ControlTower
medium
Unfair DoS for users when they call `migrate()` when borrows are paused, but users do not have debt
medium
Wrong assumption of oracle's decimals causes positions to be liquidatable, when they are not, and may cause DoS for other functionalities as well
Jul '25
high
medium
Jun '25
May '25
high
high
high
high
high
high
medium
medium
Apr '25
Mar '25
Feb '25
high
Incorrect Reward Claim Logic in FeeCollector::claimRewards Causes Denial of Service
high
Treasury Balance Tracking Bypass in FeeCollector
high
Ineffective Time-Weighted Average Implementation in Fee Distribution
medium
Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations
medium
Multiple Token Management Lets Withdraw a Token Different than Deposited Token
low
`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types
low
Treasury's allocated funds not tracked during withdrawals leads to accounting issue where recepient can receive more than allocated funds.
Jan '25
Dec '24
Nov '24
Oct '24
Sep '24
high
high
medium
Jul '24