Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
CodeHawks
Hats Finance
Jan '25
Jul '24
Jun '24
medium
Rebase token, increasing or decreasing, resulting Potential Locked token in `tokenExclusionManager` or Last user unable to `claimRemovedTokens`
medium
OOG on `claimRemovedTokens` loop due to potential large gap between `lastClaimedUserId` and `_currentSnapshotId`
low
Incomplete `TokenWhitelistManagement` implementation
low
Transferring ownership of a Portfolio is not updated (reflected) on `PortfolioInfolList`
Mar '24
Feb '24
Jan '24
low
Create Pool in Mock Distribution is missing validations; allowing duplicates, wrong decreaseInterval value and payoutStart value
low
The `editPool()` lacks a sanity check on the `payoutStart` parameter leading to incorrect or unfair reward distributions
low
LayerZeroEndpoint.send() in L1Sender.sol may revert if the user does not provide enough native gas as specified
Dec '23
Oct '23
Sep '23
Jul '23
70.69 USDC • 4 total findings • CodeHawks • chainnue
#25
high
Liquidation Is Prevented Due To Strict Implementation of Liqudation Bonus
medium
staleCheckLatestRoundData() does not check the status of the Arbitrum sequencer in Chainlink feeds.
medium
DSC protocol can consume stale price data or cannot operate on some EVM chains
gas
DSC Mint will either return true or revert, thus checking `minted` status in `mintDcs` is unnecessary
2,083.58 USDC • 5 total findings • CodeHawks • chainnue
medium
Fee-on-transfer tokens aren't supported
medium
[H-01] Lack of emergency withdraw function when no arbiter is set
medium
Fixed `i_arbiterFee` can prevent payment
gas
`tokenContract`is always an unsafe input, for fairness, it is recommended to add a whitelist for token
gas
Add an optional deadline parameter for dispute process
Jun '23
May '23
high
`StableOracleWBTC`'s is using ETH/USD priceFeed, resulting less USSD on minting with WBTC collateral
high
Missing crucial modifier on `mintRebalancer` and `burnRebalancer` functions
medium
Chainlink's `latestRoundData` may return stale or incorrect results
medium
StableOracleWBTC using BTC/USD chainlink oracle to price WBTC which have a potential problematic issue if WBTC depegs
Apr '23
Mar '23
Feb '23
Jan '23
Dec '22
Nov '22
Oct '22
Sep '22
Aug '22
Jul '22