Payouts
Top 50
All
Sherlock
Code4rena
CodeHawks
Mar '25
Feb '25
high
`GaugeController` does not send funds to FeeCollector disrupting fees distribution and causing loss of funds
high
Users can borrow more assets than they have deposited as collateral
high
RToken is Not Interest Bearing Due to Broken Liquidity Index Calculation
high
Gauge rewards are not transferred to gauge when distributeRewards() is called
high
Voting Power Snapshot Missing
medium
Missing Vote Frequency Control in GaugeController
medium
veRaac Token Constraint MAX_TOTAL_SUPPLY Can Be Bypassed. Vulnerability Disrupts Protocol Functionality and Undermines Governance Quorum.
medium
There is no logic checking for RAACNFT price staleness before minting it
medium
Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations
medium
Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator
medium
`veRAACToken::_updateBoostState` function sets individual user voting power instead of system-wide totals
medium
Token Accounting Mismatch Between tick() and mintRewards() in RAACMinter
medium
Incorrect Period Transition Logic in Reward Distribution
medium
Delegated Boost Persists Even If veRAAC Is Withdrawn/Reduced
medium
[L-1] Inaccurate boost calculations in `veRAACToken` due to wrong input parameter
medium
Incorrect boost calculation in `BoostController#_calculateBoost()` can be exploited to gain an unfair advantage in reward distribution
medium
Missing Predecessor Check in `executeEmergencyAction()` function
low
Limited veRaac Token Supply Triggers DoS, Hampering Proper Governance Participation.
low
Emergency Timelock Bypass: No Enforced 1-Day Delay for Emergency Actions
low
Lack of enforcement of the `MAX_TOTAL_LOCKED_AMOUNT`
low
Boost Delegation Allows Invalid Recipients on BoostController
low
Incorrect Timestamp Tracking in RAACHousePrice contract
low
`emergencyUnlockEnabled` Is Never Used, Rendering “Emergency Unlock” Ineffective
Dec '24
Nov '24