Payouts
Top 25
Top 50
All
Code4rena
Cantina
CodeHawks
Feb '25
high
RAACNFT mint function receives funds to address(this) but has no way of withdrawing them
high
Reward manipulation vulnerability in StabilityPool
high
RToken's transfer function lead to loss of funds due to incorrect math
high
NFTs Get Permanently Locked in Stability Pool After Liquidation
high
Any attempt to liquidate a user will fail, because StabilityPool does not hold crvUSD during operational lifecycle
high
Ownership Parameter Mismatch in LendingPool’s Vault Withdrawal Logic
high
Ineffective Time-Weighted Average Implementation in Fee Distribution
high
Voting Power Snapshot Missing
high
Hardcoded Exchange Rate Leading to Incorrect Deposits and Redemptions
medium
RToken.transferFrom() Does Not Scale User Balances Due to Stale Liquidity Index
medium
LendingPool deposits do not work with CurveVault due to lack of funds
medium
Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check
medium
Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations
medium
Liquidations are enabled when repayments are disabled, causing borrowers to lose funds without a chance to repay
medium
Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator
medium
Inconsistent Scaling in RToken Transfer Functions
medium
Failure to Withdraw Liquidity to RToken.sol Before Changing Curve Vault Address
medium
Fee-on-transfer token handling issue in `Treasury::deposit` leads to permanent fund loss
medium
`RAACReleaseOrchestrator::emergencyRevoke()` fails to update `categoryUsed`, leading to token lockup and incorrect accounting
medium
The `TimelockController::executeEmergencyAction()` function does not update the `_operations` mapping, which can lead to an operation being executed twice.
medium
Emergency Withdraw in veRAACToken Breaks Governance Security
low
Impossible to rescue funds from `RToken` contract
low
`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types
low
Treasury's allocated funds not tracked during withdrawals leads to accounting issue where recepient can receive more than allocated funds.
Dec '24
Aug '24
medium