Payouts
1st Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
Mar '25
Jan '25
Dec '24
high
CDS.sol#updateDownsideProtected - There is a missing access control
medium
`lastCumulativeRate` is incorrectly calculated due to wrong update of the `lastEventTime`
medium
BorrowLib.sol#calculateReturnToAbond - Under some conditions, a higher value will be subtracted from a lower one, breaking the liquidation.
Oct '24
Sep '24
medium
Aug '24
Jul '24
high
BribeRewarder.sol#deposit() will revert because of wrong check
high
Voter.sol#vote
high
Possible stuck of funds in BribeRewarder.sol
high
BribeRewards.sol#claim
medium
MlumStaking.sol#_requireOnlyOperatorOrOwnerOf is improperly implemented
medium
addToPosition #_transferSupportingFeeOnTransfer should be called at the beginning of the function
medium
A malicious user can fill the maximum bribe limit to sabotage pool voting
Jun '24
medium
medium
May '24
medium
medium
Mar '24
Feb '24
high
Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win
high
Since you can reroll with a different fighterType than the NFT you own, you can reroll bypassing maxRerollsAllowed and reroll attributes based on a different fighterType
medium
Can mint NFT with the desired attributes by reverting transaction
medium
Fighter created by mintFromMergingPool can have arbitrary weight and element
Jan '24
Dec '23
Oct '23
Sep '23
Aug '23
Jun '23