High
Total
Medium
Solo
Total
Total Earnings
#244 All Time
Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
Immunefi
Hats Finance
Jan '25
high
high
medium
high
high
high
medium
medium
Nov '24
Oct '24
Findings not publicly available for private contests.
Sep '24
high
DOS to `withdrawProtectedListing`
high
Users can manipulate the `unlock price` and their `ProtectedListingHealth`
high
Manipulating collection token's total supply to manipulate `utilizationRate`
high
Native ETH royalty can never be claimed by anyone
high
All the royalties can be looted by anyone
high
Donation fees are sandwichable in one transaction
medium
poolFee can never be set
medium
`removeFeeExemption` will always revert due to wrong validation
medium
Fees are burnt instead of deposited to uniswap implementation during unlocks
medium
Refunding unused native tokens to user is wrong
medium
Double fee charged on price modification of a liquid listing
Aug '24
Jul '24
medium
medium
medium
Jun '24
159.16 USDC • 2 total findings • Sherlock • Ironsidesec
#11
May '24
medium
Depositing `stETH` to puffer finance will revert due to wrong implementation of `PufETHAdapter._stake` call
medium
Missing stake limit validation on `RenzoAdapter._stake`
medium
Less rsETH minted than intended in volatile conditions. due to zero slippage when staking ETH to mint rsETH
medium
Slippage on `MetapoolRouter.addLiquidityOneETHKeepYt`
medium
`swapETHForYt` will revert even if contract has enough ETH to repay flashloan and refund remaining to user
Apr '24
high
Vestable ZVE amounts can be inflated or deflated to any victim despositor
high
`ZivoeRewards` lacks reward rate and balance check on `depositReward()`
high
A revoked vesting recipient can still vote with checkpoints worth `vestingAmount
high
wrong `_totalSupply` accounting causing DOS on `ZivoeRewardsVesting.withdraw` and `ZivoeRewardsVesting.revokeVestingSchedule`
high
`OCY_Convex_C.claimRewards` will revert if extra rewards > 0
medium
ZivoeRewards.sol does Inefficient reward distribution
medium
Interest payments can be skipped for at least one interval.
medium
`pushToLockerMulti` which adds liquidity to pool will fail 90% of the time due to strict allowance check
medium
Yield calculations are accounted by reading the stale ema supply amounts
Mar '24