
Payouts

2nd Places

Top 10

Top 25
All
Sherlock
Sep '25
high
Pending bucket rewards can be reset to 0 via stake/unstake every block (lastRewardIndex reset without checkpoint)
high
Cashback rewards can be claimed retroactively before program deployment leading to a loss of yield/funds
medium
Inflated emissions can be captured by staker after idle periods
medium
Retroactive mint rate increase mints past emissions at new rate
medium
Loss of yield trough severely reduced USDC cashback payouts on BNB
high
Geometric pool swap costs can be evaded through repeated small transactions leading to a loss of yield for LP's
high
Geometric exact amount out floors input via into_int(), allowing an attacker to completely drain any geometric pool
medium
DOS in XYK pool liquidity provision trough one sided initial deposit
medium
Any change in bucket size will DOS order cancellation leading to frozen user funds and halts the entire auction
medium
Integer overflow in XYK invariant computation causes denial of service for high-decimal tokens
Aug '25
Jul '25
May '25
high
Different Token Decimals on different chains are not accounted for when borrowing or repaying across chains, leading to a loss of funds for the protocol and users
high
Incorrect if clause in LendStorage::borrowWithInterest leads to cross chain borrows not being added to the borrowed amount which breaks the liquidation and LEND distribution system