Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Jan '25
Jul '24
Jan '24
high
User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated
high
The use of spot price by CoreSaltyFeed can lead to price manipulation and undesired liquidations
medium
THE USER WHO WITHDRAWS LIQUIDITY FROM A PARTICULAR POOL IS ABLE TO CLAIM MORE REWARDS THAN HE DULY DESERVES BY CAREFULLY SELECTING A `decreaseShareAmount` VALUE SUCH THAT THE `virtualRewardsToRemove` IS ROUNDED DOWN TO ZERO
medium
MinShares Slippage Parameters Are Ineffective For Initial Deposit
medium
Attacker Can Inflate LP Position Value To Create a Bad Debt Loan
medium
formPOL lacks slippage and deadline protection
medium
StakingRewards pools are not given their promised share of rewards due to incorrect calculation
medium
Minimium Collateral Check Can Be Bypassed
Nov '23
Oct '23
Sep '23
Aug '23
high
Malicious lender can use Callbacks to create Loan that cannot be repaid
high
Lender Loses Collateral from Paritailly Repaid Loans that are Defaulted if repayDirect == true
medium
When borrower rolls their loan the lender can frontrun the transaction and change the interest and duration to drain all of borrower's approved tokens
medium
RollLoan can be called on someone else's loan giving them worse conditions or defaulting them in 1 block
Apr '23
high
Reward accounting is incorrect in BathBuddy contract
high
An attacker can steal all tokens of users that use `FeeWrapper`
medium
Zero reward rate calculation impedes low-decimals token distributions
medium
Calling `ExpiringMarket.stop` and `ExpiringMarket.isClosed` functions cannot pause any functionlities of the market
Mar '23
Feb '23
Jan '23