Payouts
2nd Places
3rd Places
Top 10
All
Code4rena
Feb '22
Jan '22
high
deposit() function is open to reentrancy attacks
high
Withdrawers can get more value returned than expected with reentrant call
high
Vaults with non-UST underlying asset vulnerable to flash loan attack on curve pool
medium
Vault can't receive deposits if underlying token charges fees on transfer
medium
unsponsor, claimYield and withdraw might fail unexpectadly
medium
Changing a strategy can be bricked
Dec '21
Nov '21
medium
Frontrunning in UniswapHandler calls to UniswapV2Router
medium
Auction collateralToken won't work if token is fee-on-transfer token
medium
Bonding.sol _unbondAndBreak does not account for edge case where no tokens are returned
medium
AbstractRewardMine.sol#setRewardToken is dangerous
medium
AuctionParticipant.sol: `purchaseArbitrageTokens` should not push duplicate auctions
medium
AuctionParticipant.sol: `setReplenishingIndex` mistake could freeze unclaimed tokens
Oct '21