Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Jul '25
May '25
Apr '25
high
high
high
medium
Mar '25
Feb '25
high
Reward manipulation vulnerability in StabilityPool
high
Attackers can get most of RAACToken rewards by withdrawing dust amount from StabilityPool multiple times
high
Stability pool does not consider RToken balance increase when DEToken is withdrawn
medium
Incorrect utilization rate forces protocol to issue maximum rewards indefinitely
medium
`ReserveLibrary.getNormalizedDebt` doesn't return normalized debt
Jan '25
high
Users can claim coupons without engaging in protocol activities due to the absence of a minimum duration between `create()` and `redeem()`
high
`Pool.transferReserveToAuction()` reverts due to incorrect usage of index for current auction
high
The fee calculation which the protocol claims is incorrect and this could unfair to users
medium
User funds can be lost during `joinBalancerAndPredeposit()` access
medium
The state variable `BondToken.globalPool` is updated incorrectly via `Pool.startAuction()`
medium
The `BondToken.increaseIndexedAssetPeriod()` involves incorrect logic for updating state variable `globalPool`