
Payouts

1st Places

3rd Places

Top 10
All
Sherlock
Code4rena
Cantina
CodeHawks
Jan '26
Dec '25
high
BuilderWallet `init()` is unprotected/re-initializable, enabling takeover and theft of builder fees
medium
Self-settlement via `dispatchFrom` bypasses refund mechanism allowing underfunded debt settlement
medium
Withdrawing just before a bad debt event can increase losses for remaining liquidity providers
medium
`dispatchFrom()` Liveness DoS via `StaleOracle`: Spot Price Manipulation Blocks Liquidations, Force Exercises, and Premium Settlements
medium
Commission Share-Burn Distribution is JIT-Capturable When `builderCode == 0` (Default)
Nov '25
high
medium
medium
Oct '25
medium
medium
medium
medium
medium
Sep '25
Aug '25
Jul '25
medium
medium
medium
medium
May '25
high
Apr '25
high
high
high
high
Feb '25
high
Multiple Delegation by Double Spending Boosts and Lack of Delegation Tracking in BoostController Contract
medium
Flawed Boost Multiplier Calculation Always Yields Maximum Boost
low
Lack of enforcement of the `MAX_TOTAL_LOCKED_AMOUNT`
low
Overwriting Previous Allocations in allocateFunds May Lead to Loss of Cumulative Allocation Data
Dec '24