Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Blackthorn
Code4rena
Cantina
Feb '25
Collaborative Audit • Sherlock • hack3r-0m
Nov '24
medium
Jul '24
Feb '24
Oct '23
Collaborative Audit • Blackthorn • hack3r-0m
Jul '23
high
Reentrancy in `USDO.flashLoan()`, enabling an attacker to borrow unlimited USDO exceeding the max borrow limit
medium
`ARBTriCryptoOracle` is vulnerable to read-only reentrancy
medium
all deposit and withdraw function in Convex and Curve nativeLP Strategy, apply slippage on internal pricing; which call real-time on chain price from Curve directly and subject to MEV
Feb '23
high
while creating deposit, fee can be deducted in wrong manner if initialToken is not final token
high
faulty abi decoding from revert in catch block can lead to attacker controlled execution
medium
potentially using old price from pricefeed in oracle due to unchecked timestamp difference
medium
unsatisfiable condition in `getAdjustedLongAndShortTokenAmounts`
May '22
Jan '22
Nov '21
Oct '21
Sep '21
Aug '21