Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Code4rena
Apr '25
Feb '25
Jan '25
high
The calculation of `totalAssets()` could be wrong if `operatorFeeAmount` > 0, this can cause potential loss for the new depositors
medium
Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions
medium
User can earn rewards by frontrunning the new rewards accumulation in Ron staking without actually delegating his tokens
Dec '24
high
In `transferVesting`, the `grantorVesting.releaseRate` is calculated incorrectly, which leads to the sender being able to unlock more tokens than were initially locked.
medium
maxSellPercent can be buypassed by selling previously bought vestings at a later time
medium
Rounding error in stepDuration calculations.
medium
Large number of steps in a vesting may lead to loss of beneficiary funds or uneven vesting distribution
Oct '24
Aug '24
high
Malicious actors can manipulate the `cross_chain_callback` callback
high
There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` function
high
Anyone can manipulate user nonce (nonce_manager) in settlement contract
high
SettlementSignatureVerifier is missing check for duplicate validator signatures
medium
SettlementSignatureVerifier's required_validators is not updated, resulting in a low or high number of signatures being required
Jul '24
high
`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`
high
Wrong minting logic based on total token count across generations
medium
Lack of Slippage Protection in Dynamic Pricing Mint Function
Jun '24
Apr '24
Mar '24
Feb '24
Jan '24
Dec '23
Nov '23