Payouts
1st Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Jan '25
high
medium
medium
medium
Dec '24
high
Price Manipulation in `redeemUSDT` Function Enables Treasury Drain via Arbitrary User Input
high
Incorrect USDa Yield Redemption Due to Failure to Update `usdaGainedFromLiquidation` in Liquidation Process
high
Denial of Service (DoS) in CDS Contract Due to Unrestricted `updateDownsideProtected` Function
high
Flawed Time Check in `getOptionFeesToPay` Allows Borrowers to Extend Downside Protection After Maturity
high
Downside Protection Granted to Borrowers After Option Maturity Expiry in borrowing::withDraw
high
Downside Protection Failure in BorrowLib::withdraw Function
high
Exploitable Inconsistency Between `strikePrice` and `strikePercent` in Deposit Logic
medium
Inflated Position Sizing Due to Miscalculation in `sizeDelta` Parameter in `BorrowingLiquidation::liquidationType2`
medium
ETH Insufficiency in `BorrowLiquidation` Contract Leads to Transaction Failures During Type 2 Liquidation, Blocking Type 2 Liquidation
medium
Denial-of-Service Risk in Liquidation Type 1 Due to Exchange Rate Underflow
medium
Underflow Vulnerability in `liquidationType1` Due to Debt Exceeding Collateral Amount
medium
Incorrect `lastEventTime` Update in `_withdraw` Leading to Miscalculation of Cumulative Rate and Undercharged Debt
Oct '24
high
medium
medium
Sep '24
high
medium
medium
Aug '24
medium
medium
Jul '24
medium
Insufficient checks to confirm the correct status of the sequencerUptimeFeed
medium
A malicious User can DOS all offchain orders making them unexecutable and leaving the protocol in an insolvent state. Also all offchain Trades can also be DOSed for honest parties that do not meet the fillorder requirements (no try and catch)
low
Liquidation of accounts collateral not posible because some chainlink price feed doesn't exist or are marked as medium risk by chainlink
low
payable Modifier in TradingAccountBranch::createTradingAccountAndMulticall
May '24
Apr '24
high
Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral
high
Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine
high
Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply
high
Attacker Can Frontruns User's Withdrawals To Make Them Reverts Without Costs
Mar '24
Feb '24
Jan '24