Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
CodeHawks
Dec '23
high
A user can steal an already transfered and bridged reSDL lock because of approval
high
Not Update Rewards in `handleIncomingUpdate` Function of `SDLPoolPrimary` Leads to Incorrect Reward Calculations
medium
A user can lose funds in `sdlPoolSecondary` if tries to add more sdl tokens to a lock that has been queued to be completely withdrawn
medium
Attacker can exploit lock update logic on secondary chains to increase the amount of rewards sent to a specific secondary chain
low
Insufficient Gas Limit Specification for Cross-Chain Transfers in _buildCCIPMessage() method. WrappedTokenBridge.sol #210
low
Lack of storage gap in SDLPool.sol can lead to upgrade storage slot collision.
low
Can lock Fund for 1 sec and unlock in same transaction to gain profit
Oct '23
high
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
high
Attacker can reenter to mint all the collection supply
high
Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders
medium
Bidder Funds Can Become Unrecoverable Due to 1 second Overlap in `participateToAuction()` and `claimAuction()`
Jul '23
248.75 USDC • 2 total findings • CodeHawks • innertia
#28
May '23
Apr '23
high
Collaterals can be stacked in the contract, so if the loan defaults, the lender loses everything.
medium
Disable the liquidation function.
medium
Market owners and protocol owners can steal user funds by front-running transactions and raising commissions.
medium
Fee-on-transfer tokens cannot be deposited.
Mar '23
Oct '22
Sep '22