Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
CodeHawks
Jun '25
May '25
Apr '25
Feb '25
high
Multiple Delegation by Double Spending Boosts and Lack of Delegation Tracking in BoostController Contract
high
Delegation Boost Not Usable by Delegatees
high
Gauge period cannot be updated
high
`GaugeController` does not send funds to FeeCollector disrupting fees distribution and causing loss of funds
high
Reward manipulation vulnerability in StabilityPool
high
Incorrect Reward Claim Logic in FeeCollector::claimRewards Causes Denial of Service
high
Users can borrow more assets than they have deposited as collateral
high
RToken is Not Interest Bearing Due to Broken Liquidity Index Calculation
high
Boost Miscalculation Leads to Excess Distribution
high
Ownership Parameter Mismatch in LendingPool’s Vault Withdrawal Logic
high
Treasury Balance Tracking Bypass in FeeCollector
high
Untracked Direct Fee Transfers from RAACToken to FeeCollector Break Fee Distribution System
high
Ineffective Time-Weighted Average Implementation in Fee Distribution
high
Gauge reward system can be gamed with repeatedly stake/withdraw
medium
Missing Vote Frequency Control in GaugeController
medium
`MAX_TOTAL_SUPPLY` Bypass in `veRAACToken` via `increase()` Function
medium
Incorrect Return Values and Double Scaling in `RToken.burn` Function Leads to Denial of Service
medium
LendingPool deposits do not work with CurveVault due to lack of funds
medium
Multiple Critical Calculation And Logic Errors in `RToken::mint/burn` Function
medium
There is no logic checking for RAACNFT price staleness before minting it
medium
Emergency Withdrawal Remains Active After Cancellation
medium
Time-skew Attack in RWAGauge Weight Calculations Through Precision Gaming
medium
Multiple Token Management Lets Withdraw a Token Different than Deposited Token
medium
Cordinated group of attacker can artificially lower quorum threshold during active proposals forcing malicious proposals to pass without true majority support.
medium
Incorrect boost calculation in `BoostController#_calculateBoost()` can be exploited to gain an unfair advantage in reward distribution
medium
balanceOf(address(this)) in StabilityPool causes reward distribution to be higher than it should be
medium
Users Cannot Remove Their Own Boost Delegation, Causing Potential Lock-In
low
Missing Controller Functions in GaugeController
low
Emergency withdraw functionality in veRAACToken takes longer than expected
low
Incorrect Initialization of minBoost in BaseGauge Constructor Breaks Core Contract Functionality
low
Missing Checkpoint Reset in `veRAACToken::emergencyWithdraw` Function
low
`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types
low
Insufficient ETH Forwarding in Governance Execution Mechanism Causes Proposal Failures
low
Missing Validation for Minimum Vote Weight in `vote` Function
low
BoostController Bypasses Boost State Tracking System
Jan '25
Dec '24
medium
Nov '24
Aug '24