Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Feb '24
high
Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win
medium
NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)
medium
Fighter created by mintFromMergingPool can have arbitrary weight and element
Jan '24
Oct '23
Mar '23
Feb '23