Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Cantina
CodeHawks
Mar '25
Feb '25
Jan '25
medium
Dec '24
high
Out-of-Bounds Array Access in `_calculateQuantAMMVariance` with Odd Number of Assets and Vector Lambda
high
Critical: Malicious user can delete all Users Deposited Liquidity.
high
Owner fee will be locked in `UpliftOnlyExample` contract due to incorrect recipient address in `UpliftOnlyExample::onAfterSwap`
high
GradientBasedRules will not work for >=4 assets with vector lambdas
medium
“Uplift Fee” Incorrectly Falls Back to Minimum Fee Due to Integer Division
medium
Transferring deposit NFT doesn't check if the receiver exceeds the 100 deposit limit
medium
If main oracle is removed from approved list it will keep returning not stale but invalid data (0 value)
medium
incorrect length check in `_setGradient` will DOS manual setting of `intermediateGradientState` after pool initialization
low
Inconsistent timestamp storage when the LPNFT is transferred.
low
Incorrect event emitted in `setUpdateWeightRunnerAddress()` function
low
Inconsistent event data in `WeightsUpdated` emissions
high
Duplicate orderId Risk in OracleLess, Bracket, and StopLimit Contracts
high
Vulnerability in OracleLess, Bracket, StopLimit: Modify cancelled/filled orders
high
Malicious users can sell tokens of others in OracleLess
high
Arbitrary execution in OracleLess::fillOrder enables token theft
medium
DOS vulnerability in OracleLess due to unbounded pending orders
Nov '24
high
Oct '24
high
Sep '24
Aug '24