Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Aug '24
Jul '24
high
DoS Vulnerability in the `deposit` Function of `BribeRewarder` contract
high
Incorrect validation in the vote function allows users to vote if the remaining lock time is less than the epoch time
medium
Incorrect validation in the _requireOnlyOperatorOrOwnerOf function of the MlumStaking contract allows unauthorized access
medium
Incorrect validation logic in `harvestPositionsTo` function restricts functionality in `MlumStaking`
Jun '24
655.57 USDC • 3 total findings • Sherlock • blackhole
#7
high
Missing check for slippage in the _sellStakedUSDe function will result in a loss of funds
high
Missing check for slippage in the _executeInstantRedemption function will result in a loss of funds
high
Incorrect value calculation in `_getValueOfSplitFinalizedWithdrawRequest` due to missing decimals conversion
May '24
high
Unauthorized access to `batchUpdateAccountToken` function allows arbitrary token updates in AccountFacet
high
The `redeemFee` is not properly deducted in `_executeRedeemStakeToken` Function
medium
Keepers can steal additional execution fee from users in `processExecutionFee` function
medium
The `minRedeemAmount` validation check does not consider the actual redeem amount
Apr '24
Mar '24
Jan '24
Jul '23
May '23