Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Mar '25
Feb '25
high
configDirC not freed
high
Malicious proposer can include empty transactions in a valid proposal
high
Chain halt as VerifyVoteExtensionHandler is not guaranteed to run
high
ASA-2025-003
high
postBatch: inflating votingPower
high
Malicious validator can steal withdraw tokens
medium
requestor can prevent postResult
medium
postRequest can be front run
Jan '25
Findings not publicly available for private contests.
Dec '24
high
execute : target can be any address, including Token. stealing funds
high
Orders created in same block will override each other
high
OracleLess.createOrder passes wrong owner to procureTokens
medium
cancelOrder and adminCancelOrder can be blocked by using blacklisted recipient address. permanent dos
medium
PythOracle.currentValue will return only if price is stale
medium
OracleLess missing maxPendingOrders check, leading to OOG in fillOrder, cancelOrder
Oct '24