Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Cantina
CodeHawks
Jul '25
Jun '25
high
Unauthorized Refund Claims for Non-EVM Addresses
high
Attacker can steal an high-value token due to lack of swap execution
high
An attacker will steal protocol funds from reverted cross-chain txs
medium
Incorrect Swap Amount After Fee Deduction
medium
ETH Revert Handling Failure in Cross-Chain Operations
medium
ETH Address Approval Attempt Causes All Zeta Swaps to Revert
medium
Platform Fee Bypass in Zeta Swap Execution
medium
An attacker will cause transaction reverts for users by spoofing Uniswap V2 pool existence
medium
Untrusted `onAbort`/`onRevert` call will allow overwriting of legitimate external ID for cross-chain refund logic
medium
Bitcoin Address Truncation in Revert Message Causes Failed Refunds
May '25
medium
medium
medium
medium
medium
Apr '25
high
high
high
high
high
medium
high
Mar '25
high
medium
Feb '25
medium
high
RAACNFT mint function receives funds to address(this) but has no way of withdrawing them
high
Reward manipulation vulnerability in StabilityPool
high
RToken's transfer function lead to loss of funds due to incorrect math
high
NFTs Get Permanently Locked in Stability Pool After Liquidation
medium
Incorrect utilization rate forces protocol to issue maximum rewards indefinitely
medium
Incorrect DebtToken totalSupply Scaling Breaks Interest Rate Calculations
medium
Users Can Lose Funds and Collateral by Repaying Loans After Liquidation Grace Period Expiry
medium
`RToken::calculateDustAmount` are incorrectly calculated, leading to not be able to transfer the accrued dust amount
medium
getNormalizedDebt will return a wrong Amount when Timedelta is 0.
medium
`ReserveLibrary.getNormalizedDebt` doesn't return normalized debt
low
Incorrect Timestamp Tracking in RAACHousePrice contract