Payouts
1st Places
2nd Places
3rd Places
All
Code4rena
Jul '24
Jun '24
May '24
Apr '24
Mar '24
Jan '24
Nov '23
Oct '23
Sep '23
Jun '23
May '23
Apr '23
Mar '23
Jan '23
Dec '22
high
Malicious user can steal all assets in BondNFT
high
reentrancy attack during mint() function in Position contract which can lead to removing of the other user's limit orders or stealing contract funds because initId is set low value
medium
Centralization risks: owner can freeze withdraws and use timelock to steal all funds
high
`LPDA` price can underflow the price due to bad settings and potentially brick the contract
high
`saleReceiver` and `feeReceiver` can steal refunds after sale has ended
medium
Editions should be checked if they are actually deployed from the legitimate Escher721Factory
medium
ETH will get stuck if all NFTs do not get sold.
medium
Sale contracts can be bricked if any other minter mints a token with an id that overlaps the sale
Nov '22
high
BringUnusedETHBackIntoGiantPool can cause stuck ether funds in Giant Pool
high
Giant pools can be drained due to weak vault authenticity check
medium
Incorrect checking in _assertUserHasEnoughGiantLPToClaimVaultLP
medium
Freezing of funds - Hacker can prevent users withdraws in giant pools
medium
Giant pools cannot receive ETH from vaults