Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Jan '25
Dec '24
high
In `transferVesting`, the `grantorVesting.releaseRate` is calculated incorrectly, which leads to the sender being able to unlock more tokens than were initially locked.
medium
Incorrect referral fee calculations
medium
maxSellPercent can be buypassed by selling previously bought vestings at a later time
Nov '24
Oct '24
Aug '24
Jul '24
high
Availability of deposit invariant can be bypassed
medium
Discrepency b/w the `lastRewadTime` and the `lastAllPoolUpdate` can allow for incorrect reward distribution to pools if `registerRewardDeposit` deposits less assets
medium
Incorrect address is used as `spender` for ERC20 permit signature verification
medium
`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`
Jun '24
May '24
high
Availability of deposit invariant can be bypassed
medium
Discrepency b/w the `lastRewadTime` and the `lastAllPoolUpdate` can allow for incorrect reward distribution to pools if `registerRewardDeposit` deposits less assets
medium
Incorrect address is used as `spender` for ERC20 permit signature verification
medium
`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`
Apr '24
Mar '24
Feb '24
Jan '24