Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
Cantina
CodeHawks
Hats Finance
Aug '25
Collaborative Audit • Sherlock • Kirkeelee
Jul '25
medium
Jun '25
May '25
high
A cross-chain user can drain protocol funds by exploiting token decimal mismatches.
high
A user can supply collateral via flashloan/flashmint, initiate a cross-chain borrow, and redeem collateral in a single transaction to drain protocol funds.
high
Users can repeatedly claim the same LEND rewards due to lack of reset after claim.
high
User can evade liquidation and bridge funds by exploiting cross-chain borrow/collateral invariant
high
Liquidation can fail permanently due to incorrect `destEid` in `findCrossChainCollateral`, causing liquidator funds to be stuck.
high
Repayment logic incorrectly updates same-chain borrow balances for cross-chain borrows.
high
LEND rewards are calculated after balance updates, leading to inaccurate and unfair reward distribution.
high
A user can over-borrow on multiple chains by exploiting asynchronous cross-chain borrow requests
medium
A user can drain the contract’s ETH balance by spamming cross-chain borrow requests without supplying any collateral.
medium
Borrow limit check may be overly restrictive due to redundant interest scaling in borrow calculation.
Findings not publicly available for private contests.
Apr '25
Collaborative Audit • Sherlock • Kirkeelee
Mar '25
Feb '25
122.06 USDC • 2 total findings • Code4rena • Kirkeelee
#25
Jan '25
Findings not publicly available for private contests.
Dec '24
Nov '24
Findings not publicly available for private contests.
Oct '24
Findings not publicly available for private contests.
Sep '24
Aug '24
Jul '24
May '24
Apr '24
Feb '24
Jan '24
Dec '23
Jul '23
May '23