
Payouts

1st Places

3rd Places

Top 10
All
Sherlock
Code4rena
Cantina
Jan '26
high
UniswapPriceOracle.validatePrice() TWAP Calculation Flaw
high
Variable Overwrite in checkPoolAndGetCenterPrice() Creates Dead-Code Deviation Check, Leaving All V3 Protocol-Owned Liquidity Operations Unprotected
medium
Services can earn undeserved rewards by manipulating checkpoint timing during reward droughts
medium
Balancer oracle deadlock from cumulative price weight
medium
Uniswap oracle validateprice can be griefed per block via `sync()`
Dec '25
high
BuilderWallet `init()` is unprotected/re-initializable, enabling takeover and theft of builder fees
medium
Self-settlement via `dispatchFrom` bypasses refund mechanism allowing underfunded debt settlement
medium
Withdrawing just before a bad debt event can increase losses for remaining liquidity providers
medium
`dispatchFrom()` Liveness DoS via `StaleOracle`: Spot Price Manipulation Blocks Liquidations, Force Exercises, and Premium Settlements
medium
Commission Share-Burn Distribution is JIT-Capturable When `builderCode == 0` (Default)
Nov '25
Oct '25
medium
medium
medium
medium
medium