Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Code4rena
CodeHawks
Immunefi
Nov '23
low
1.37 USDC • 1 total finding • Code4rena • Madalad
#31
Oct '23
Sep '23
Aug '23
high
The same signature can be used in different `distribution` implementation causing that the caller who owns the signature, can distribute on unauthorized implementations
medium
Blacklisted STADIUM_ADDRESS address cause fund stuck in the contract forever
medium
Malicious/Compromised organiser can reclaw all funds, stealing work from supporters
low
If a winner is blacklisted on any of the tokens they can't receive their funds
low
Lack of checking the existence of the Proxy contract
low
Centralization Risk for trusted organizers
Jul '23
131.57 USDC • 5 total findings • CodeHawks • Madalad
#13
medium
staleCheckLatestRoundData() does not check the status of the Arbitrum sequencer in Chainlink feeds.
medium
All of the USD pair price feeds doesn't have 8 decimals
medium
Too many DSC tokens can get minted for fee-on-transfer tokens.
medium
Protocol can break for a token with a proxy and implementation contract (like `TUSD`)
low
Pragma isn't specified correctly which can lead to nonfunction/damaged contract when deployed on Arbitrum
5.61 USDC • 3 total findings • CodeHawks • Madalad
#80
high
Tokens can be stolen from other users who have approved Magnetar
high
Potential 99.5% loss in `emergencyWithdraw()` of two Yieldbox strategies
medium
token mights stuck in MagnetarMarketModule contract if the asset doesn't support cross-chain operation
medium
`MagnetarV2#burst` double counts `msg.value` for `TOFT_WRAP` operation, making the transaction revert unless the user overpays
medium
`StargateStrategy#_withdraw`: ether becomes trapped in the contract whenever a user withdraws
medium
`StargateStrategy#_currentBalance` calculation is incorrect and may lead to DoS
medium
all deposit and withdraw function in Convex and Curve nativeLP Strategy, apply slippage on internal pricing; which call real-time on chain price from Curve directly and subject to MEV
medium
Some actions inside MagnetarV2.burst will not work because msg.value is used inside delegate call
medium
Potential loss of value in YieldBox's `depositETHAsset()`
medium
[HB09] `emergencyWithdraw` on all strategy contracts useless without a pause mechanism
Jun '23
May '23
medium
[M-01] Some functions in Talos contracts does not allow user to supply slippage and deadline, which may cause swap revert
medium
RestakeToken function is not permissionless
medium
Lack of slippage protection can lead to significant loss of user funds
medium
Protocol fees can become trapped indefinitely inside Talos vault contracts
high
Missing deadline checks allow pending transactions to be maliciously executed
high
Incorrect initialization of `ethOracle`
high
Anyone can arbitrarily inflate the USSD `totalSupply` and cause DoS
medium
Chainlink's latestRoundData return stale or incorrect result
medium
Oracles will return the wrong price for asset if underlying aggregator hits minAnswer
Apr '23
Mar '23
Feb '23
Jan '23
Dec '22