Payouts
1st Places
2nd Places
Top 10
All
Code4rena
Apr '24
high
Incorrect withdraw queue balance in TVL calculation
high
Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps
medium
Fetched price from the oracle is not stored in `xRenzoDeposit`
medium
Deposits will always revert if the amount being deposited is less than the bufferToFill value
medium
Price updating mechanism can break
Mar '24
Feb '24
high
Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions
medium
Malicious users can prevent holders from claiming their rewards during a reward cycle by skipping it.
medium
`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.