Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Feb '25
Jan '25
Dec '24
high
Malicious users will steal funds by using other user's signatures when withdrawing from CDS
high
Attacker will steal USDT funds from treasury through unvalidated price input in `CDS.sol#redeemUSDT()`
high
An attacker will freeze CDS functionality through downsideProtected manipulation
high
Liquidator will cause loss of borrowers.
high
The owner cannot withdraw the interest from liquidation.
high
Admin will lose `eth` or fail to liquidate unhealthy position.
high
An attacker can steal funds from the treasury.
medium
An attacker will manipulate `omniChainData.cdsPoolValue` by breaking protocol
medium
The `borrowing.lastCumulateRate` update error will cause protocol loss.
medium
Incorrect application of `lastCumulativeRate` will increase borrower's debt or decrease borrower's repay amount unexpectedly.