Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Feb '25
Collaborative Audit • Sherlock • S3v3ru5
Oct '24
Sep '24
Aug '24
high
Missing validations on CCIP parameters in the `WinnablesTicketManager.cancelRaffle` and `propagateRaffleWinner` allows attackers to cause loss of funds
high
Attacker can cancel raffles before they can be created leading to DoS
high
Missing updates to `_lockedETH` state variable in the `WinnablesTicketManager.refundPlayer` function lead to loss of funds
medium
Admin can overwrite owner of the winning ticket using integer overflow
medium
WinnablesPrizeManager.setCCIPCounterpart function allows admins to send their own winner messages to the prize manager
medium
The `WinnablesTicket.ownerOf` function might always revert with Out-of-Gas for certain tickets leading to loss of funds