Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
CodeHawks
Mar '25
Jan '25
medium
WSTETH is not supported by the protocol
medium
User can always inflate the `totalSellReserveAmount` variable to block the auction from being ended
medium
USDC blacklist may be a problem in Auction
medium
Precision loss in `Pool::getRedeemAmount` will result in users redeeming less collateral than they should
Dec '24
Nov '24
Oct '24
Aug '24
Jul '24
high
Availability of deposit invariant can be bypassed
high
AuraVault inherits AccessControl BUT does not call the _setupRole() function in it's constructor to set the initial roles, this leads to a complete DOS of the important claim function rendering the contract unable to claim rewards
medium
Incorrect calculation of `newCumulativeIndex` in function `calcDecrease`
medium
`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`
Jun '24
May '24
high
Availability of deposit invariant can be bypassed
high
AuraVault inherits AccessControl BUT does not call the _setupRole() function in it's constructor to set the initial roles, this leads to a complete DOS of the important claim function rendering the contract unable to claim rewards
medium
Incorrect calculation of `newCumulativeIndex` in function `calcDecrease`
medium
`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`
Apr '24
Mar '24
Jan '24