Payouts
Top 25
Top 50
All
Code4rena
CodeHawks
Oct '23
high
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
high
Attacker can reenter to mint all the collection supply
medium
getPrice `salesOption` 2 can round down to the lower barrier, skipping the last time period
medium
Auction payout goes to AuctionDemo contract owner, not the token owner
Sep '23
Aug '23
high
The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP
high
The peg stability module can be compromised by forcing lowerDepeg to revert.
medium
Inaccurate swap amount calculation in ReLP leads to stuck tokens and lost liquidity
medium
Change of `fundingDuration` causes "time travel" of `PerpetualAtlanticVault.nextFundingPaymentTimestamp()`
Jul '23
high
Tokens with less than 18 decimals allow for draining of funds
high
Sandwich attack to steal all ERC-20 tokens in the Fees contract
medium
Precision loss allows users to giveLoans to pools with less collateral then required
medium
The `borrow` and `refinance` functions can be front-run by the pool lender to set high interest rates
0.00 USDC • 1 total finding • CodeHawks • degensec
#163