Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
Apr '24
Mar '24
Feb '24
Jan '24
high
Unauthorized Access to setCurves Function
medium
Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.
medium
Withdrawing with amount = 0 will forcefully set name and symbol to default and disable some functions for token subject
medium
If a user sets their curve token symbol as the default one plus the next token counter instance it will render the whole default naming functionality obsolete
Dec '23
Oct '23
Sep '23
May '23
Mar '23
Feb '23
Jan '23
Dec '22
high
MinipoolManager: node operator can avoid being slashed
high
Hijacking of node operators minipool causes loss of staked funds
medium
`requireNextActiveMultisig` will always return the first enabled multisig which increases the probability of stuck minipools
medium
Coding logic of the contract upgrading renders upgrading contracts impractical
Nov '22
medium
Front-running admin setPrice call allows a single compromised oracle to set any price, allowing the oracle manipulator to drain all protocol funds
medium
NTokenMoonBirds Reserve Pool Cannot Receive Airdrops
medium
During oracle outages or feeder outages/disagreement, the `ParaSpaceFallbackOracle` is not used
medium
Centralization risk: admin can with rug the project by removing asset and price manipulation on oracle.
medium
MintableIncentivizedERC721 and NToken do not comply with ERC721, breaking composability
Oct '22
Sep '22