Payouts
1st Places
2nd Places
Top 10
All
Code4rena
Cantina
CodeHawks
Jun '25
Mar '25
Feb '25
high
medium
medium
Dec '24
high
high
high
medium
medium
medium
Oct '24
medium
medium
Sep '24
medium
medium
medium
Aug '24
high
high
high
high
medium
medium
medium
Jul '24
high
An attacker can bypass the challenge period during LPP finalization
high
LPP metadata can be altered after the challenge period is over, allowing incorrect states to be proven
high
The LPP challenge period can cause malicious and freeloader claims to be uncounterable and can also cause freeloader claims to be abused to entrap honest challengers
medium
The `MIPS` doesn't implement `ADD`, `ADDI`, and `SUB` instructions correctly
May '24
Apr '24
high
`SNXConnector.sol` TVL calculation is incorrect.
high
`NoyaValueOracle.getValue` returns an incorrect price when a multi-token route is used
high
Numerous errors when calculating the TVL for the MorphoBlue connector
high
In Dolomite, when opening a borrow position, the holding position in the Registry will never be updated due to the removePosition flag being set to true
medium
The modifier `onlyExistingRoute` works incorrectly
medium
Incorrect modifier condition
medium
Lack of Slippage Controls in retrieveTokensForWithdraw Function
Mar '24
Jan '24
high
high
high
medium
medium
medium
medium
high
Attack to make ````CurveSubject```` to be a ````HoneyPot````
high
Unrestricted claiming of fees due to missing balance updates in `FeeSplitter`
high
Unauthorized Access to setCurves Function
medium
Protocol and referral fee would be permanently stuck in the Curves contract when selling a token
medium
A subject creator within a single block can claim holder fees without holding due to unprotected reentrancy path
medium
onBalanceChange causes previously unclaimed rewards to be cleared
Dec '23
Nov '23
Oct '23
Sep '23
Aug '23