whitehat
High
Total
Medium
Total Earnings
#507 All Time
Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
Jan '25
7,604.41 USDC • 3 total findings • Cantina • yashar
#12
high
medium
Aug '24
155.09 USDC • 2 total findings • Sherlock • Yashar
#26
Attacker can DoS the `SuperPoolFactory`
De-Whitelisted tokens remain usable as collateral due to incomplete asset revocation
Jul '24
3.52 USDC • 3 total findings • Code4rena • yashar
#52
WhenNotPaused modifier in the CDPVault can be bypassed by users
Malicious actor can abuse the minimum shares check in `StakingLPEth` and cause DoS or locked funds for the last user that withdraws
`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`
230.94 USDC • Sherlock • Yashar
#89
40.06 USDC • 3 total findings • Sherlock • Yashar
#42
The voting mechanism for the periods that have a bribe will be DoSed
Attacker can manipulate the `lockDuration` of other users positions
Attackers can drain the rewards
Jun '24
416.09 USDC • 1 total finding • Sherlock • Yashar
#6
Stakers Funds Will Be Permanently Locked Within the Contract if a Validator is Tombstoned
Mar '24
565.16 USDC • 1 total finding • Code4rena • yashar
#11
Freezed Chain will never be unfreeze since `StateTransitionManager::unfreezeChain` is calling `freezeDiamond` instead of `unfreezeDiamond`.
Jan '24
8.62 USDC • Code4rena • yashar
#63
Oct '23
2,468.82 USDC • 3 total findings • Code4rena • yashar
Malicious users are able to bypass the Tax payment using making a Fake BasicActions Contract
Updating `SafeManager` address in the `Vault721` will disable NFV minting
`ODSafeManager#allowSAFE()` cannot be executed either by the proxy contract or any other address.
Aug '23
0.15 USDC • 1 total finding • Code4rena • yashar
#124
The peg stability module can be compromised by forcing lowerDepeg to revert.