Payouts
3rd Places
Top 10
Top 25
All
Code4rena
Cantina
May '24
Feb '24
medium
medium
Nov '23
208.48 USDC • 2 total findings • Code4rena • glcanvas
#16
Oct '23
Sep '23
Aug '23
Jul '23
high
Attacker can pass duplicated reward token addresses to steal the reward of contract `twTAP.sol`
high
Attacker can prevent rewards from being issued to gauges for a given epoch in TapiocaOptionBroker
medium
Incorrect `eligibleAmount` for `AirdropBroker` Phase 3
medium
`TapiocaOptionLiquidityProvision.registerSingularity()` not checking for duplicate assetIds leading to multiple issues.
medium
possible reeentrancy if rewardToken is ERC777 or execute arbitrary code on senders/receivers using hooks
Mar '23
Jan '23
high
Protocol fees can be withdrawn multiple times in `Erc20Quest`
medium
Possible scenario for Signature Replay Attack
medium
RabbitHoleReceipt's address might be changed therefore only manual mint will be available
medium
DOS risk if enough tokens are minted in Quest.claim can lead, at least, to transaction fee lost
medium
User may loose rewards if the receipt is minted after quest end time