Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Jul '23
Jun '23
high
Incorrectly implemented modifiers in LybraConfigurator.sol allow any address to call functions that are supposed to be restricted
medium
Volatile prices and lack of checks on `rigidRedemption()` can cause users to purchase stETH at unwanted prices
medium
If `ProtocolRewardsPool` is insufficient in EUSD, users will not be able to calim any rewards
medium
Due to inappropriately short `votingPeriod` and `votingDelay`, it is near impossible for the governance to function correctly.
medium
Incorrect function call in LybraRETHVault's getAssetPrice
medium
It is possible to manipulate WETH/LBR pair to claim reward of the users which shouldn't be claimed
medium
Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called