Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Apr '23
Oct '22
high
Any user can receive arbitrarily large amount of Illuminate tokens for a small deposit by exploiting reentrancy in Lender
high
Users' redemptions of Illuminate can be hijacked by front-running and minting more Illuminate
high
Reentrancy and using user-supplied address in Sense variant of redeem() allows for manipulating holdings and increasing redemption payouts
high
Redemption pause is not enforced in authRedeem() and autoRedeem()
high
ERC5095's redeem() and withdraw() pre-maturity don't consume caller's tokens
medium
MarketPlace.setPrincipal(...) doesn't work for Notional