Payouts
Top 10
Top 25
Top 50
All
Code4rena
CodeHawks
Apr '24
high
Incorrect withdraw queue balance in TVL calculation
high
Incorrect calculation of queued withdrawals can deflate TVL and increase ezETH mint rate
medium
Lack of slippage and deadline during withdraw and deposit
medium
Fixed hearbeat used for price validation is too stale for some tokens
medium
Withdrawals and Claims are meant to be pausable, but it is not possible in practice
Feb '24
Jan '24
high
Due to missing checks on minimum gas passed through LayerZero, executions can fail on the destination chain
high
Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.
medium
Potential loss of capital due to fixed fee calculations
medium
Missing access control on UTB:receiveFromBridge allows UTB swaps to be executed without spending bridge fees while bypassing fee/swap instruction signature verification
Dec '23
high
Rewards can be drained because of lack of access control
high
Looping over unbounded `pendingStakes` array can lead to permanent DoS and frozen funds
medium
Fees are hardcoded to 3000 in ExactInputSingleParams
medium
Attacker can force reduce `minAmountOut` from vault swaps, making they vulnerable to being sandwiched.
Oct '23