Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Nov '22
high
Incorrect accounting in SyndicateRewardsProcessor results in any LP token holder being able to steal other LP tokens holder's ETH from the fees and MEV vault.
high
Sender transferring GiantMevAndFeesPool tokens can afterward experience pool DOS and orphaning of future rewards
medium
GiantPool batchRotateLPTokens function: Minimum balance for rotating LP Tokens should by dynamically calculated
medium
GiantMevAndFeesPool.previewAccumulatedETH function: "accumulated" variable is not updated correctly in for loop leading to result that is too low
medium
Calling `updateNodeRunnerWhitelistStatus` function always reverts
medium
Freezing of funds - Hacker can prevent users withdraws in giant pools
medium
GiantPool should not check ETH amount on withdrawal
medium
Withdrawing wrong LPToken from GiantPool leads to loss of funds
medium
OwnableSmartWallet: Multiple approvals can lead to unwanted ownership transfers
high
Non-existing revenue contract can be passed to claimRevenue to send all tokens to treasury
high
Repaying a line of credit with a higher than necessary claimed revenue amount will force the borrower into liquidation
medium
Lender can trade claimToken in a malicious way to steal the borrower's money via claimAndRepay() in SpigotedLine by using malicious zeroExTradeData
medium
Mutual consent cannot be revoked and stays valid forever
medium
Mistakenly sent eth could be locked
medium
Variable balance ERC20 support
medium
Borrower/Lender excessive ETH not refunded and permanently locked in protocol
Oct '22