A carnivore bear mongrel which...
... turns into a persimmon werewolf once in a fortnight.
High
Total
Medium
Total
Total Earnings
#1164 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
Mar '25
Jan '25
Dec '24
high
Malicious user can grief legitimate users by permanently locking their pre-approved ERC20 funds in the StopLimit contract
high
Griefing other users' ERC20 approvals and permits through unsanitized external call in OracleLess:fillOrder
high
Malicious users can create orders, charging other users, to be exeucted at unfavorable prices
high
Almost infinitely doubling the aBondBalance by calling `ABondToken.transferFrom`, where `from` is the attacker's 1st account
high
`CDS::updateDownsideProtected` lacks access control, and hence allows for DoS'ing `_updateCurrentTotalCdsDepositedAmount` and therefore `deposit`
high
Contrary to the intended schedule, the users can renew options as often as they wish
Nov '24
Oct '24
high
Sep '24
Aug '24
Jul '24
high
The _totalStaked tracker calculation is incorrect and will be inflated due to the improper logic in the writeOffDebt function of the UserManager contract, leading to wrong Comptroller gInflationIndex being calculated and wrong user rewards being issued
medium
Users can get vouched for (entrusted) maliciously by utilizing the ERC1155Voucher's onERC1155BatchReceived function which lacks proper access control checks
May '24
Apr '24
high
`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`
medium
PendleConnector.sol::supply doesn't pass a valid slippance protection min
medium
The modifier `onlyExistingRoute` works incorrectly
medium
Incorrect modifier condition
medium
Balancer flashloan contract can be DOSed completely by sending 1 wei to it
Jan '24