High
Total
Medium
Total
Total Earnings
#139 All Time
Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Aug '24
high
User could withdraw more than supposed to, forcing last user withdraw to fail
medium
Users are incentivized to not withdraw immediately after the market is closed.
medium
Role providers can bypass intended restrictions and lower expiry set by other providers
medium
`FixedTermLoanHook` looks at `block.timestamp` instead of `expiry`
medium
Inconsistency across multiple repaying functions causing lender to pay extra fees.
Feb '24
high
A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters
high
Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`
medium
DoS in `MergingPool::claimRewards` function and potential DoS in `RankedBattle::claimNRN` function if called after a significant amount of rounds passed.
Findings not publicly available for private contests.
Sep '23
Aug '23
high
If `claimDefaulted` is called before `claimRepaid` all of `loan.unclaimed` will be lost
high
If `loan.callback == true`, lender can force all repayments to revert and force loan into default
medium
Anyone can accept new terms by calling `rollLoan` due to lack of access control.
medium
Lender can front-run `rollLoan` and call `provideNewTermsForRoll` with unfavorable terms
high
`ReLPContract` wrongfully assumes protocol owns all of the liquidity in the UniswapV2 pool
high
Improper precision of strike price calculation can result in broken protocol
high
The peg stability module can be compromised by forcing lowerDepeg to revert.
medium
reLP() mintokenAAmount the calculations are wrong.
high
When adding a gauge, its initial value has to be set by an admin or all voting power towards it will be lost
high
Voters from VotingEscrow can vote infinite times in vote_for_gauge_weights() of GaugeController
high
If governance removes a gauge, user's voting power for that gauge will be lost.
medium
Users can front-run calls to `change_gauge_weight` to gain extra voting power
Jun '23
Findings not publicly available for private contests.
May '23
Apr '23
Mar '23