Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Mar '25
Feb '25
Jan '25
Findings not publicly available for private contests.
Dec '24
high
execute : target can be any address, including Token. stealing funds
high
Orders created in same block will override each other
high
OracleLess.createOrder passes wrong owner to procureTokens
medium
cancelOrder and adminCancelOrder can be blocked by using blacklisted recipient address. permanent dos
medium
PythOracle.currentValue will return only if price is stale
medium
OracleLess missing maxPendingOrders check, leading to OOG in fillOrder, cancelOrder
Oct '24