Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Jul '25
May '25
high
Attackers can steal LEND from the CoreRouter
high
supply() records wrong amount in totalInvestment
high
Users are underpaid when redeeming
high
An attacker can steal most of the assets through borrowing
high
Unfair liquidations can occur
medium
Lack of minimum position size can lead to bad debt for the protocol
Mar '25
Feb '25
Jan '25
Dec '24
high
Malicious users can steal from the protocol and freeze other users' funds
high
Malicious users can drain the protocol by creating multiple orders in one block
high
Not resetting approval after a call lets malicious users steal from the protocol
medium
currentValue() will revert because of a wrongly implemented stale price check
high
Borrowers' debt can be higher than expected because calculateCumulativeRate() has no access control and does not update lastEventTime
high
Malicious users can steal USDT from the treasury
high
Malicious users can DOS the protocol by setting downsideProtected to a large value
high
Abond's transferFrom() function updates wrong user state
high
Malicious users can pay less option fees
medium
Malicious users can block admins from accessing setter functions
Nov '24
Oct '24
Sep '24
Aug '24
Apr '24