Payouts
2nd Places
3rd Places
Top 10
All
Code4rena
Cantina
CodeHawks
Immunefi
Feb '25
Dec '24
high
high
medium
medium
medium
medium
Oct '24
high
high
medium
high
high
medium
medium
Aug '24
high
medium
medium
medium
medium
medium
medium
Jul '24
high
`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`
high
The maximum number of generations is infinite
high
Number of entities in generation can surpass the 10k number
high
Wrong minting logic based on total token count across generations
medium
Forger Entities can forge more times than intended
medium
Pause and unpause functions are inaccessible
medium
Excess ETH from `forgingFee` can get stuck in `EntityForging` under certain situations
medium
Discrepancy between nfts minted, price of nft when a generation changes & position of `_incrementGeneration()` inside `_mintInternal()` & `_mintNewEntity()`
high
Single plot can be occupied by multiple renters
high
Failure to Update Dirty Flag in transferToUnoccupiedPlot Prevents Reward Accumulation On Valid Plot
high
Invalid validation in _farmPlots function allowing a malicious user repeated farming without locked funds
medium
Users can farm on zero-tax land if the landlord locked tokens before the LandManager deployment
May '24
medium
medium
medium
Feb '24
high
medium
low
medium
Jan '24
high
medium
Nov '23
high
User funds can be lost in favor of Zeta protocol during a CCTX due to contracts being paused
high
Disabling outbound transactions is ineffective and allows for Zeta token theft
medium
Possible index out of range in GetVoterIndex could cause ballot to never finalize due to panic
medium
When updating gas, if one chain fails, the others should continue to be updated instead of being skipped.
medium
UpdateSystemContract is not copying gasPriceByChainId state variable to the new upgraded which will halt ZRC20 token withdraw until system contract is updated accordingly
medium
Outbound zEVM cross-chain messages ignore the user-specified gas limit and may fail with an out-of-gas error
medium
User not refunded for failed Zeta gas payment in cross chain transaction
low
low
Oct '23
Aug '23
Jul '23
Jun '23
Apr '23
Mar '23
Feb '23